vendor:
TFTP server TFTPDWIN
by:
SkD
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: TFTP server TFTPDWIN
Affected Version From: 2000.4.2
Affected Version To: 2000.4.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 98/Me/2000/XP/2003
ProSysInfo TFTP server TFTPDWIN <= 0.4.2 Universal Remote Buffer Overflow Exploit
This exploit targets ProSysInfo TFTP server TFTPDWIN version 0.4.2 and below. It allows a remote attacker to execute arbitrary code on the target system by sending a specially crafted request. The exploit takes advantage of a buffer overflow vulnerability in the software. The exploit author has provided a universal payload that works on all Windows versions. The exploit uses a custom shellcode to execute the 'calc' command. The author warns that they have no responsibility for any damage caused by using this exploit.
Mitigation:
Update to a patched version of the software (version 0.4.3 or higher).