vendor:
IntelliTamper
by:
cN4phux
7.8
CVSS
HIGH
Local SEH Overwrite Exploit
119
CWE
Product Name: IntelliTamper
Affected Version From: 02.07
Affected Version To: 02.08
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
Unknown
IntelliTamper 2.07/2.08 (MAP File) 0-day Local SEH Overwrite Exploit
This exploit is for IntelliTamper 2.07/2.08 which is a 0-day Local SEH Overwrite Exploit. The bug was discovered by cN4phux and tested on IntelliTamper 2.07/2.08 / win32 SP3 FR. The shellcode used is Windows Execute Command (calc) from metasploit.com. The exploit is written in Python and the debugger output shows that the EIP is overwritten and an attempt to read from address 41414141 is made, causing the program to crash. The exploit is written in Python and the debugger output shows that the EIP is overwritten and an attempt to read from address 41414141 is made, causing the program to crash.
Mitigation:
The user should update to the latest version of IntelliTamper to mitigate this vulnerability.