Description
Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog to trigger a reverse shell with system privileges.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Shubham Singh
References
www.exploit-db.com/exploits/45355 (ExploitDB-45355)
flash.dvd-photo-slideshow.com/ (Product Reference)
www.vulncheck.com/...-maker-professional-buffer-overflow-seh (VulnCheck Advisory: Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH)