← Advisories

AutoPlay v1.33 (autoplay.ini) Local Buffer Overflow Exploit (SEH)

High
Advisory ID
ZSL-2011-4994
Release Date
15 February 2011
Vendor
Naugher Software - http://www.naughter.com
Affected Version
1.33
CVE
N/A
Tested On
Microsoft Windows 7 Ultimate
Summary

AutoPlay is a shareware application used for making autorun.ini files that can be edited and stored to compact disks.

Description

The program suffers from a buffer overflow vulnerability when openinng autorun file (.ini), as a result of adding extra bytes to parts of the edited file, giving the atackers the possibility for an arbitrary code execution on the affected system. Also the buffer overflow vulnerability allows the atacker to bypass Structured Exception Handling (SEH) protection mechanism.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Dame Jovanoski
References
Changelog
15.02.2011Initial release
16.02.2011Added reference [1], [2], [3] and [4]
06.03.2011Added reference [5] and [6]