vendor:
Tomabo MP4 Player
by:
@yokoacc, @nudragn, @rungga_reksya
N/A
CVSS
HIGH
SEH Based Stack Overflow
121
CWE
Product Name: Tomabo MP4 Player
Affected Version From: 3.11.2006
Affected Version To: 3.11.2006
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP, 7, 8, and 8.1
2015
Tomabo MP4 Player 3.11.6 SEH Based Stack Overflow
This exploit targets a stack overflow vulnerability in Tomabo MP4 Player version 3.11.6 or below. By opening a specially crafted m3u file, an attacker can execute arbitrary code on the target system. The exploit payload is a bind TCP meterpreter shell on port 4444.
Mitigation:
Update to the latest version of Tomabo MP4 Player