vendor:
Internet Download Manager
by:
Dark-Puzzle (Souhail Hammou)
N/A
CVSS
N/A
Memory Corruption
119
CWE
Product Name: Internet Download Manager
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: N/A
CPE: a:tonec:internet_download_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Service Pack 2 FR 32-bits, Windows 7 FR 64-bits
2012
Internet Download Manager All Versions – Memory Corruption Vulnerability
A vulnerability in Internet Download Manager (IDM) allows attackers to execute arbitrary code by importing a specially crafted IDM export file. The vulnerability exists due to a boundary error when processing the file, which can be exploited to cause a stack-based buffer overflow. Successful exploitation of this vulnerability may allow attackers to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of Internet Download Manager.