Description
Faleemi Desktop Software 1.8 contains a local buffer overflow vulnerability in the System Setup dialog that allows attackers to bypass DEP protections through structured exception handling exploitation. Attackers can inject a crafted payload into the Save Path for Snapshot and Record file field to trigger a buffer overflow and execute arbitrary code via ROP chain gadgets.
Problem types
Product status
Credits
bzyo
References
www.exploit-db.com/exploits/46269 (ExploitDB-46269)
www.faleemi.com/ (Official Product Homepage)
www.vulncheck.com/...re-local-buffer-overflow-seh-dep-bypass (VulnCheck Advisory: Faleemi Desktop Software 1.8 Local Buffer Overflow SEH DEP Bypass)