vendor:
WM Downloader
by:
Hadji Samir
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: WM Downloader
Affected Version From: 3.1.2.2
Affected Version To: 3.1.2.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:wm_downloader:wm_downloader
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
WM Downloader 3.1.2.2 (.m3u) File WinXP Sp3(fr) Buffer Overflow stack Exploit
WM Downloader 3.1.2.2 is vulnerable to a buffer overflow stack exploit when a specially crafted .m3u file is opened. This exploit was tested on Windows XP SP3 (fr). The exploit code contains a shellcode that executes calc.exe when the vulnerable application is opened.
Mitigation:
Update to the latest version of WM Downloader.