vendor:
TuneClone
by:
Achilles
7.5
CVSS
HIGH
Local Seh Exploit
119
CWE
Product Name: TuneClone
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2019
TuneClone Local Seh Exploit
This exploit allows an attacker to execute arbitrary code and gain a bind shell on port 3110 by exploiting a vulnerability in TuneClone software. The exploit leverages a buffer overflow vulnerability to overwrite the Structured Exception Handler (SEH) and gain control of the program flow.
Mitigation:
The vendor should release a patch or update to fix the buffer overflow vulnerability. Users should update to the latest version of TuneClone to mitigate this vulnerability.