vendor:
Internet Download Manager
by:
f3ci
9,3
CVSS
HIGH
SEH Buffer Overflow (Unicode)
119
CWE
Product Name: Internet Download Manager
Affected Version From: 6.28 Build 17
Affected Version To: 6.28 Build 17
Patch Exists: YES
Related CWE: N/A
CPE: a:internet_download_manager:internet_download_manager:6.28
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 x86
2017
Internet Download Manager 6.28 Build 17 – ‘Find file’ SEH Buffer Overflow (Unicode)
Internet Download Manager 6.28 Build 17 is vulnerable to a SEH Buffer Overflow (Unicode) vulnerability. An attacker can exploit this vulnerability by crafting a malicious payload and sending it to the vulnerable application. The payload is then executed in the context of the application, allowing the attacker to gain control of the affected system.
Mitigation:
Upgrade to the latest version of Internet Download Manager 6.28 Build 17.