关键漏洞信息 Advisory: CORELAN-11-004 Disclosure Date: April 30, 2011 Product: MJM Core Multimedia Suite (Core Player) Version: 2.4 (and earlier) Vendor: MJM Soft URL: http://www.mjmsoft.net/ Platform: Windows XP, Vista, Windows 7 Type of Vulnerability: Stack Buffer Overflow Risk Rating: Medium Issue Fixed in Version: Not fixed Vulnerability Discovered by: rick2600 Vulnerability Discovery Date: April 13, 2011 漏洞详情 Vulnerability Details: Core Player 2.4 is prone to a buffer overflow when parsing a malformed .s3m file. This will overwrite an exception handler record and allows for the execution of arbitrary code. 利用代码 Exploit/PoC: Metasploit / modules / exploits / windows / fileformat / mjm_coreplayer2011_s3m.rb