vendor:
Excel Password Recovery
by:
Achilles
7.5
CVSS
HIGH
SEH Local Exploit
119
CWE
Product Name: Excel Password Recovery
Affected Version From: 8.3.2001
Affected Version To: 8.3.2001
Patch Exists: NO
Related CWE:
CPE: a:passfab:excel_password_recovery:8.3.1
Platforms Tested: Windows XP SP3
2019
PassFab Excel Password Recovery SEH Local Exploit
This exploit takes advantage of a vulnerability in PassFab Excel Password Recovery software version 8.3.1 running on Windows XP SP3. By providing specially crafted input, an attacker can trigger a buffer overflow and overwrite the Structured Exception Handler (SEH) to gain control of the program execution flow. This exploit replaces the SEH with a pop pop ret address in the SoftwareLog.dll module, allowing the execution of arbitrary code. The payload used in this example is a shellcode that opens the Windows calculator.
Mitigation:
Update to the latest version of PassFab Excel Password Recovery software. Avoid running the software on unsupported operating systems.