Description
AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted into the application.
Problem types
Product status
Credits
bzyo
References
www.exploit-db.com/exploits/45151 (ExploitDB-45151)
agatasoft.com/ (Official Product Homepage)
www.vulncheck.com/...oft-auto-pingmaster-buffer-overflow-seh (VulnCheck Advisory: AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH)