vendor:
Installshield
by:
e.b.
7.5
CVSS
HIGH
SEH Overwrite
CWE
Product Name: Installshield
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 (fully patched) English, IE6
Macrovision Installshield isusweb.dll SEH Overwrite Exploit
This exploit targets the isusweb.dll file in Macrovision Installshield. It overwrites the Structured Exception Handling (SEH) to gain control of the program flow. The exploit includes shellcode that executes the calc.exe program. Tested on Windows XP SP2 (fully patched) English with IE6 and isusweb.dll version 5.1.100.47363.
Mitigation:
Apply the latest patches for Macrovision Installshield and update isusweb.dll to a version that is not vulnerable to SEH Overwrite exploits.