module

eSignal and eSignal Pro File Parsing Buffer Overflow in QUO

Disclosed
2011-09-06
Created
2018-05-30

Description

The software is unable to handle the "" files (even those
original included in the program) like those with the registered
extensions QUO, SUM and POR. Successful exploitation of this
vulnerability may take up to several seconds due to the use of
egghunter. Also, DEP bypass is unlikely due to the limited space for
payload. This vulnerability affects versions 10.6.2425.1208 and earlier.

Authors

Luigi Auriemma
TecR0c tecr0c@tecninja.net
mr_me steventhomasseeley@gmai.com

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/windows/fileformat/esignal_styletemplate_bof
msf exploit(esignal_styletemplate_bof) > show targets
...targets...
msf exploit(esignal_styletemplate_bof) > set TARGET < target-id >
msf exploit(esignal_styletemplate_bof) > show options
...show and set options...
msf exploit(esignal_styletemplate_bof) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.