PictureTrails Photo Editor GE.exe 2.0.0 – ‘.bmp’ Crash (PoC)

  • 作者: redknight99
    日期: 2016-03-02
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39518/
  • # Exploit Title: PictureTrail Photo Editor GE.exe 2.00 - ./bmp Crash PoC
    # Date: 01-03-2016
    # Exploit Author: redknight99
    # Vendor Homepage: http://www.picturetrail.com/
    # Software Link: http://www.picturetrail.com/downloads/photoeditor200.exe
    # Version: 2.0.0
    # Tested on: Windows 7, 10
    # CVE : Unknown
    
    Picture Trail Photo editor fails to properly parse .bmp header height and width values. 
    Negative height and width values cause a program crash (memory corruption) and SEH corruption. Remote code execution may be possible.
    
    
    Proof of Concept:
    https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39518.zip