Description
Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory through the 'File' input parameter. Attackers can craft a malicious payload with 268 bytes to trigger code execution, bypassing DEP and overwriting memory addresses to launch calc.exe.
Problem types
Product status
Credits
PovlTekstTV
References
www.exploit-db.com/exploits/48678 (ExploitDB-48678)
www.ashkon.com/startup_manager.html (Product Webpage)
www.vulncheck.com/...rtup-manager-file-local-buffer-overflow (VulnCheck Advisory: Simple Startup Manager 1.17 - 'File' Local Buffer Overflow)