vendor:
iworkstation
by:
Sanjeev Gupta
9,3
CVSS
HIGH
SEH Exploit
119
CWE
Product Name: iworkstation
Affected Version From: 9.3.2.1.4
Affected Version To: 9.3.2.1.4
Patch Exists: YES
Related CWE: N/A
CPE: a:iworkstation:iworkstation:9.3.2.1.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2020
iworkstation Version 9.3.2.1.4 seh exploit
This exploit is for iworkstation Version 9.3.2.1.4. It is a SEH exploit which uses a POP ESI instruction to gain control of the execution flow. The exploit code is written in Perl and is used to create a malicious .pls file which can be used to trigger the vulnerability.
Mitigation:
The vendor has released a patch to address this vulnerability.