vendor:
KMPlayer
by:
metacom
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: KMPlayer
Affected Version From: 3.8.0.117
Affected Version To: 3.8.0.117
Patch Exists: YES
Related CWE: N/A
CPE: KMPlayer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2020
KMPlayer 3.8.0.117 Buffer Overflow
KMPlayer 3.8.0.117 is vulnerable to a buffer overflow vulnerability. The vulnerability is triggered when a specially crafted playlist is opened in the KMPlayer Playlist Editor. This causes a stack-based buffer overflow, which allows an attacker to execute arbitrary code. The exploit code contains 250 bytes of junk data followed by a return address pointing to the JMP ESP instruction in kernel32.dll. The exploit code also contains a shellcode that executes calc.exe.
Mitigation:
Update to the latest version of KMPlayer.