vendor:
Zoom Player
by:
Debasish Mandal
7.5
CVSS
HIGH
Memory Corruption and Arbitrary Code Execution
CWE
Product Name: Zoom Player
Affected Version From: Zoom Player v8.5
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
2013
Inmatrix Ltd. Zoom Player Crafted JPEG File Memory Corruption and Arbitrary Code Execution Exploit
This exploit targets a vulnerability in Inmatrix Ltd. Zoom Player v8.5. By crafting a malicious JPEG file, an attacker can trigger a memory corruption issue and execute arbitrary code on the targeted system.
Mitigation:
The vendor has patched this issue and removed the affected version from their site. Users are advised to update to the latest version of Zoom Player to mitigate this vulnerability.