vendor:
XMPlay
by:
s7acktrac3
7.5
CVSS
HIGH
Code Execution
CWE
Product Name: XMPlay
Affected Version From: 3.8.2003
Affected Version To: 3.8.2003
Patch Exists: NO
Related CWE: Reserved
CPE:
Platforms Tested: Windows XP SP3
2018
XMPlay 3.8.3 – ‘.m3u’ Code Execution (PoC)
This exploit allows an attacker to execute arbitrary code by creating a specially crafted '.m3u' file and loading it into XMPlay. The exploit takes advantage of a vulnerability in XMPlay version 3.8.3, allowing the attacker to search through memory for a payload and eventually launch calc.exe.
Mitigation:
Update XMPlay to a version that includes a fix for this vulnerability.