Description
Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to bypass SafeSEH protections and execute arbitrary commands with application privileges.
Problem types
Product status
Credits
Bobby Cooke
References
www.exploit-db.com/exploits/48346 (ExploitDB-48346)
www.vulncheck.com/...rm-clock-stack-overflow-via-seh-unicode (VulnCheck Advisory: Atomic Alarm Clock 6.3 Stack Overflow via SEH Unicode)