vendor:
RM Downloader
by:
Felipe Winsnes
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: RM Downloader
Affected Version From: 3.1.3.2.2010.06.13
Affected Version To: 3.1.3.2.2010.06.13
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 (x86)
2020
RM Downloader 3.1.3.2.2010.06.13 – ‘Load’ Buffer Overflow (SEH)
This exploit takes advantage of a buffer overflow vulnerability in RM Downloader version 3.1.3.2.2010.06.13. By crafting a specially crafted payload and pasting it into the 'Load' parameter of the application, an attacker can trigger a buffer overflow and potentially execute arbitrary code.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users are advised to avoid using RM Downloader version 3.1.3.2.2010.06.13 or to use alternative software.