Exploit PictureTrails Photo Editor GE.exe 2.0.0 - '.bmp' Crash (PoC)

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
39518
Проверка EDB
  1. Пройдено
Автор
REDKNIGHT99
Тип уязвимости
DOS
Платформа
WINDOWS
CVE
N/A
Дата публикации
2016-03-02
PictureTrails Photo Editor GE.exe 2.0.0 - '.bmp' Crash (PoC)
Код:
# Exploit Title: PictureTrail Photo Editor GE.exe 2.00 - ./bmp Crash PoC
# Date: 01-03-2016
# Exploit Author: redknight99
# Vendor Homepage: http://www.picturetrail.com/
# Software Link: http://www.picturetrail.com/downloads/photoeditor200.exe
# Version: 2.0.0
# Tested on: Windows 7, 10
# CVE : Unknown

Picture Trail Photo editor fails to properly parse .bmp header height and width values. 
Negative height and width values cause a program crash (memory corruption) and SEH corruption. Remote code execution may be possible.


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39518.zip
 
Источник
www.exploit-db.com

Похожие темы