vendor:
River Past Cam Do
by:
Chris Au
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: River Past Cam Do
Affected Version From: 3.7.2006
Affected Version To: 3.7.2006
Patch Exists: NO
Related CWE:
CPE: a:flexhex:river_past_cam_do:3.7.6
Platforms Tested: Windows XP SP3
2019
River Past Cam Do 3.7.6 Local Buffer Overflow in Activation Code
This exploit takes advantage of a buffer overflow vulnerability in the activation code of River Past Cam Do 3.7.6. By generating a malicious activation code and pasting it into the application, an attacker can execute arbitrary code, such as launching the calculator (calc.exe) in this example.
Mitigation:
Vendor should release a patch to fix the buffer overflow vulnerability. Users should update to the latest version of the software.