vendor:
PowerCHM
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: PowerCHM
Affected Version From: 5.7
Affected Version To: 5.7
Patch Exists: Yes
Related CWE: N/A
CPE: a:dawningsoft:powerchm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
PowerCHM 5.7 (hhp) Local Buffer Overflow Exploit
PowerCHM is a software used to create CHM files from Html Files, Text Files, Microsoft Word Documents and Adobe Acrobat Document. This exploit is a local buffer overflow exploit which is tested on WinXP Pro SP2 (English). It creates a file called 'Watchmen.hhp' which contains a header and a buffer overflow code. The buffer overflow code contains a shellcode which is 8B EC 33 FF 57 C6 45 FC 63 C6 45 FD 6D C6 45 FE 64 C6 45 F8 01 8D 45 FC 50 B8 C7 93 BF 77 FF D0 and is followed by 41 bytes of padding and a return address of 0x4212EDE8.
Mitigation:
Update to the latest version of PowerCHM.