vendor:
Movie Player Pro SDK ActiveX
by:
shinnai
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: Movie Player Pro SDK ActiveX
Affected Version From: 6.8.0.0
Affected Version To: 6.8.0.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP3, Windows 2000 Professional SP4
Viscom Software Movie Player Pro SDK ActiveX 6.8 Remote Buffer Overflow
A stack-based buffer overflow occurs when you pass to "strFontName" parameter a string overly long than 24 bytes which leads into EIP overwrite allowing the execution of arbitrary code in the context of the logged on user. This happens because an inadequate space is stored into the buffer intended to receive the font name.
Mitigation:
Update to a version that has patched this vulnerability.