Description
RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload with an egg hunter technique to bypass memory protections and execute commands like launching calc.exe.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Paras Bhatia
References
www.exploit-db.com/exploits/48628 (ExploitDB-48628)
github.com/x00x00x00x00/RMDownloader_2.50.60 (Software v2.50.60 Archive)
rm-downloader.software.informer.com/ (Software Informer Product Page)
www.vulncheck.com/...m-downloader-load-local-buffer-overflow (VulnCheck Advisory: RM Downloader 2.50.60 2006.06.23 - 'Load' Local Buffer Overflow)