vendor:
Prime95
by:
crash_manucoot
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Prime95
Affected Version From: 29.4b8
Affected Version To: 29.4b8
Patch Exists: NO
Related CWE:
CPE: a:mersenne:prime95:29.4b8
Platforms Tested: Windows 10 Pro x64 SPANISH, Windows 7 Home Premium x86 SPANISH, Windows XP SP3 SPANISH
2018
Prime95 Local Buffer Overflow (SEH)
The exploit takes advantage of a local buffer overflow vulnerability in Prime95. By sending a specially crafted buffer, an attacker can overwrite the Structured Exception Handler (SEH) to gain control of the program execution flow. This allows the attacker to execute arbitrary code or commands on the target system.
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of Prime95. It is also recommended to have proper input validation and boundary checks in place to prevent buffer overflows.