vendor:
iMesh
by:
rgod
7,5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: iMesh
Affected Version From: 7.1.0.x
Affected Version To: 7.0.0.x
Patch Exists: YES
Related CWE: N/A
CPE: a:imesh:imesh
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2007
iMesh <= 7.1.0.x IMWebControl Class (IMWeb.dll 7.0.0.x) remote heap exploit
iMesh is a file sharing and online social network. It uses a proprietary, centralized, P2P protocol. iMesh is owned by an American company iMesh, Inc. and maintains a development center in Israel. This vulnerability is caused by passing an empty value to ProcessRequestEx method. By hijacking the ECX register to an arbitrary value, an access violation can be triggered when reading 0D0D0D0D. This exploit adds an administrative account using various stages of heap spray.
Mitigation:
Upgrade to the latest version of iMesh