vendor:
Quick Player
by:
mr_me, sinn3r
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Quick Player
Affected Version From: Quick Player v1.2
Affected Version To: Quick Player v1.2
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows XP SP3 ENG
Not provided
Quick Player v1.2 Unicode Buffer Overflow
This exploit takes advantage of a buffer overflow vulnerability in Quick Player v1.2. It allows an attacker to execute arbitrary code on a vulnerable system. The exploit uses a bind shell payload to establish a TCP shell on port 4444. The metasploit framework is used to generate the payload. The exploit has been tested on Windows XP SP3 ENG.
Mitigation:
Apply the latest security patches and updates for Quick Player. Avoid running the software on untrusted networks.