vendor:
Mercury/32
by:
void
7.5
CVSS
HIGH
Stack Overflow
CWE
Product Name: Mercury/32
Affected Version From: Mercury/32 v4.52
Affected Version To: Mercury/32 v4.52
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP
Mercury/32 v4.52 IMAPD SEARCH command Post-Auth Stack Overflow Exploit
This exploit takes advantage of a stack overflow vulnerability in the IMAPD SEARCH command of Mercury/32 v4.52. By sending a specially crafted payload, an attacker can trigger a stack overflow and gain remote code execution on the target system.
Mitigation:
Upgrade to a patched version of Mercury/32.