vendor:
POP Peeper
by:
Stack
7.5
CVSS
HIGH
SEH Overwrite
CWE
Product Name: POP Peeper
Affected Version From: 3.4.0.0
Affected Version To: 3.4.0.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Unknown
POP Peeper 3.4.0.0 .eml file Universal SEH Overwrite Exploit
This exploit is for POP Peeper version 3.4.0.0 and targets a universal SEH (Structured Exception Handling) overwrite vulnerability. The exploit is triggered by opening a message or using the Ctrl + O command and selecting a specially crafted .eml file. Upon successful exploitation, the exploit executes a payload that launches the Windows Calculator application. This exploit was developed by Stack and credited to Mountassif Moad. Special thanks are given to Simo, SOft, Jadi, and Str0ke.
Mitigation:
Apply the latest patch or update to the affected software version. Do not open or interact with untrusted .eml files.