vendor:
WinRar
by:
ATmaCA
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: WinRar
Affected Version From: WinRar 2.x series
Affected Version To: WinRar 2.x series
Patch Exists: NO
Related CWE: Not provided
CPE: a:progroup_software:winrar
Platforms Tested:
2004
WinRar local buffer overflow exploit V1.0
This exploit allows an attacker to execute arbitrary code on a target system by exploiting a buffer overflow vulnerability in WinRar. The exploit takes advantage of a crafted RAR header and launches a local cmd.exe shell. The targets for this exploit are WinXP SP1 user32.dll [0x77D718FC] and WinXP SP2 user32.dll [0x77D8AF0A]. The exploit also requires the presence of WinRar 2.x series. The system() function from msvcrt.dll is used to execute the shellcode.
Mitigation:
Upgrade to WinRar 3.x series or later.