vendor:
RM Downloader
by:
b0telh0
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: RM Downloader
Affected Version From: 3.0.2.1
Affected Version To: 3.0.2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:mini-stream:rm_downloader
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
RM Downloader 3.0.2.1 (.asx) Local Buffer Overflow (SEH)
A buffer overflow vulnerability exists in RM Downloader 3.0.2.1 when a specially crafted .asx file is loaded. This could allow an attacker to execute arbitrary code on the vulnerable system. The vulnerability is due to insufficient bounds checking of user-supplied data when parsing the .asx file. An attacker can exploit this vulnerability by enticing a user to open a malicious .asx file.
Mitigation:
Upgrade to the latest version of RM Downloader 3.0.2.1 or later.