vendor:
Quantum Streaming Player
by:
e.b.
7.5
CVSS
HIGH
SEH Overwrite
119
CWE
Product Name: Quantum Streaming Player
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2007-4722
CPE:
Platforms Tested: Windows XP SP2 (fully patched) English, IE6
2007
Move Networks Quantum Streaming Player SEH Overwrite Exploit
This exploit takes advantage of a vulnerability in the Move Networks Quantum Streaming Player, allowing an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code. The exploit is written in JavaScript and uses shellcode to execute the 'calc.exe' program on a Windows XP SP2 system. The shellcode is limited to around 400 bytes.
Mitigation:
To mitigate this vulnerability, users should update to a patched version of the Move Networks Quantum Streaming Player.