module
ALLPlayer M3U Buffer Overflow
Disclosed | Created |
---|---|
10/09/2013 | 05/30/2018 |
Disclosed
10/09/2013
Created
05/30/2018
Description
This module exploits a stack-based buffer overflow vulnerability in
ALLPlayer 5.8.1, caused by a long string in a playlist entry.
By persuading the victim to open a specially-crafted .M3U file, a
remote attacker could execute arbitrary code on the system or cause
the application to crash. This module has been tested successfully on
Windows 7 SP1.
ALLPlayer 5.8.1, caused by a long string in a playlist entry.
By persuading the victim to open a specially-crafted .M3U file, a
remote attacker could execute arbitrary code on the system or cause
the application to crash. This module has been tested successfully on
Windows 7 SP1.
Authors
metacomMike CzumakGabor Seljan
Platform
Windows
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:
msf > use exploit/windows/fileformat/allplayer_m3u_bof msf /(f) > show actions ...actions... msf /(f) > set ACTION < action-name > msf /(f) > show options ...show and set options... msf /(f) > run

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.