vendor:
MediaCoder
by:
Karn Ganeshen
7.5
CVSS
HIGH
SEH Exploit
CWE
Product Name: MediaCoder
Affected Version From: 0.8.43.5852
Affected Version To: 0.8.43.5852
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Vista SP2
MediaCoder 0.8.43.5852 – .m3u SEH Exploit
This exploit allows an attacker to execute arbitrary code on a target system by exploiting a vulnerability in MediaCoder version 0.8.43.5852. By sending a specially crafted .m3u file, an attacker can trigger a stack-based buffer overflow, leading to a SEH overwrite and control over the program flow. This exploit has been tested on Windows Vista SP2.
Mitigation:
Update to a patched version of MediaCoder.