module

TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability

Disclosed
10/28/2008
Created
05/30/2018

Description

This module exploits a stack-based buffer overflow vulnerability
in the latest version 3.5 of TugZip archiving utility.
In order to trigger the vulnerability, an attacker must convince someone
to load a specially crafted zip file with TugZip by double click or file open.
By doing so, an attacker can execute arbitrary code as the victim user.

Authors

Stefan MarinLincolnTecR0c mr_me

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

    msf > use exploit/windows/fileformat/tugzip
    msf /(p) > show actions
        ...actions...
    msf /(p) > set ACTION < action-name >
    msf /(p) > show options
        ...show and set options...
    msf /(p) > run
  
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.