vendor:
Win10 MailCarrier
by:
Lance Biggerstaff
7.5
CVSS
HIGH
Remote Buffer Overflow
Buffer Overflow
CWE
Product Name: Win10 MailCarrier
Affected Version From: 2.51
Affected Version To: 2.51
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2019
Win10 MailCarrier 2.51 – ‘POP3 User’ Remote Buffer Overflow
This exploit allows an attacker to remotely trigger a buffer overflow in the 'POP3 User' field of Win10 MailCarrier version 2.51. By exploiting this vulnerability, an attacker can gain unauthorized access and control over the affected system. The exploit code is written in Python and includes a payload generated using msfvenom. It should be noted that different versions of Windows 10 may have different offsets, and sometimes the exploit needs to be run twice to successfully pop a shell.
Mitigation:
The vendor has not provided any specific mitigation steps for this vulnerability. It is recommended to update to the latest version of Win10 MailCarrier or use an alternative software.