Vulnerability & Exploit Database

Back to search

BlazeVideo HDTV Player Pro v6.6 Filename Handling Vulnerability

This module exploits a vulnerability found in BlazeVideo HDTV Player's filename handling routine. When supplying a string of input data embedded in a .plf file, the MediaPlayerCtrl.dll component will try to extract a filename by using PathFindFileNameA(), and then copies whatever the return value is on the stack by using an inline strcpy. As a result, if this input data is long enough, it can cause a stack-based buffer overflow, which may lead to arbitrary code execution under the context of the user.

Free Metasploit Download

Get your copy of the world's leading penetration testing tool

 Download Now

Module Name

exploit/windows/fileformat/blazedvd_hdtv_bof

Authors

  • b33f
  • sinn3r <sinn3r [at] metasploit.com>

References

Targets

  • BlazeVideo HDTV Player Pro v6.6.0.3

Platforms

  • windows

Reliability

Development

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use exploit/windows/fileformat/blazedvd_hdtv_bof msf exploit(blazedvd_hdtv_bof) > show targets ...targets... msf exploit(blazedvd_hdtv_bof) > set TARGET <target-id> msf exploit(blazedvd_hdtv_bof) > show options ...show and set options... msf exploit(blazedvd_hdtv_bof) > exploit