vendor:
WinRAR
by:
c0d3r, kaveh razavi
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: WinRAR
Affected Version From: WinRAR 3.3.0 and below
Affected Version To: WinRAR 3.3.0 and below
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Unknown
WinRAR 3.3.0 and below local BOF exploit
This is a local buffer overflow exploit for WinRAR version 3.3.0 and below. The exploit uses a jmp esp instruction in various DLLs to gain control of the program flow. The exploit also includes Metasploit shellcode to establish a reverse shell on port 4444.
Mitigation:
Use the latest version of WinRAR.