vendor:
SDP Downloader
by:
Cyber-Zone and His0k4
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SDP Downloader
Affected Version From: 2.3.0
Affected Version To: 2.3.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:sdp_downloader:sdp_downloader:2.3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Pro SP3 (EN)
2010
SDP Downloader v2.3.0 (.ASX) Local Buffer Overflow Exploit (SEH)
This exploit is for SDP Downloader v2.3.0 (.ASX) Local Buffer Overflow Exploit (SEH). It is a SEH based exploit which uses a malicious ASX file to trigger the buffer overflow. The exploit code is written in Python and uses a shellcode to execute a calculator.
Mitigation:
The user should update the software to the latest version and use a reliable antivirus software.