vendor:
TFTP Server
by:
Karn Ganeshen
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: TFTP Server
Affected Version From: 1.4
Affected Version To: 1.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Vista SP2
TFTP Server 1.4 – WRQ Buffer Overflow Exploit [Egghunter]
This exploit targets TFTP Server version 1.4 and utilizes a buffer overflow vulnerability to execute arbitrary code. It uses an Egghunter technique to find and execute the payload.
Mitigation:
Update to a patched version of TFTP Server to fix this vulnerability.