header-logo
Suggest Exploit
vendor:
PictureTrail Photo Editor GE.exe
by:
redknight99
7,5
CVSS
HIGH
SEH Corruption
Unknown
CWE
Product Name: PictureTrail Photo Editor GE.exe
Affected Version From: 2.0.0
Affected Version To: 2.0.0
Patch Exists: NO
Related CWE: Unknown
CPE: a:picturetrail:picturetrail_photo_editor_ge.exe
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7, 10
2016

PictureTrail Photo Editor GE.exe 2.00 – ./bmp Crash PoC

Picture Trail Photo editor fails to properly parse .bmp header height and width values. Negative height and width values cause a program crash (memory corruption) and SEH corruption. Remote code execution may be possible.

Mitigation:

No known mitigation or remediation for this vulnerability
Source

Exploit-DB raw data:

# Exploit Title: PictureTrail Photo Editor GE.exe 2.00 - ./bmp Crash PoC
# Date: 01-03-2016
# Exploit Author: redknight99
# Vendor Homepage: http://www.picturetrail.com/
# Software Link: http://www.picturetrail.com/downloads/photoeditor200.exe
# Version: 2.0.0
# Tested on: Windows 7, 10
# CVE : Unknown

Picture Trail Photo editor fails to properly parse .bmp header height and width values. 
Negative height and width values cause a program crash (memory corruption) and SEH corruption. Remote code execution may be possible.


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39518.zip