vendor:
Office Writer
by:
Julien Ahrens
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Office Writer
Affected Version From: 2012 8.1.0.3385
Affected Version To: 2012 8.1.0.3385
Patch Exists: NO
Related CWE: CVE-2013-3934
CPE: a:kingsoft:office_writer:2012:8.1.0.3385
Platforms Tested: WinXP-GER, Win7-GER, Win8-EN
2013
Kingsoft Office Writer v2012 8.1.0.3385 .wps Buffer Overflow Exploit (SEH)
This script creates a .wps file which exploits the vulnerability described in CVE-2013-3934 and bypasses SafeSEH protection.
Mitigation:
Apply the necessary patch or update to a non-vulnerable version.