vendor:
MakeSFX.exe
by:
John Page aka hyp3rlinx
N/A
CVSS
N/A
Stack Based Buffer Overflow
Unknown
CWE
Product Name: MakeSFX.exe
Affected Version From: v1.44 (Mar 19 2001)
Affected Version To: v1.44 (Dec 10 2009)
Patch Exists: NO
Related CWE:
CPE: freeextractor.sourceforge.net/FreeExtractor/MakeSFX.exe
Platforms Tested:
Unknown
Stack Based Buffer Overflow in MakeSFX.exe
The '/title' argument when supplied an overly long payload will overwrite NSEH & SEH exception handlers causing buffer overflow, allowing the execution of arbitrary shellcode. This vulnerability can be exploited by replacing a local .bat file with a malicious one.
Mitigation:
Unknown