vendor:
Publish-It
by:
Muhamad Fadzil Ramli
7.5
CVSS
HIGH
SEH Buffer Overflow
CWE
Product Name: Publish-It
Affected Version From: 3.6d
Affected Version To: 3.6d
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 x86 - Version 6.1.7600
2014
Publish-It 3.6d – SEH Buffer Overflow
This exploit takes advantage of a buffer overflow vulnerability in Publish-It 3.6d. By opening a specially crafted .pui file with the 'Automatic Preview' option enabled, an attacker can trigger a stack-based buffer overflow, potentially allowing for remote code execution. The exploit is in the form of a .pui file named 'motiv.pui'.
Mitigation:
Disable the 'Automatic Preview' option in Publish-It 3.6d. Update to a patched version if available.