vendor:
Mercury Audio Player
by:
His0k4
7.5
CVSS
HIGH
Stack Overflow
CWE
Product Name: Mercury Audio Player
Affected Version From: Mercury Audio Player 1.21
Affected Version To: Mercury Audio Player 1.21
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Pro SP3
Unknown
Mercury Audio Player 1.21 (.b4s) Local Stack Overflow
This exploit is for Mercury Audio Player 1.21 (.b4s) which allows local stack overflow. The exploit code was created by His0k4. It has been tested on Windows XP Pro SP3 (EN). The vulnerability allows an attacker to execute arbitrary code by overflowing the stack. The exploit uses a jump instruction to the address 0x7C868667 in kernel32.dll. It also includes some nops (no-operation instructions) for padding.
Mitigation:
Unknown