15 lines
No EOL
637 B
Text
15 lines
No EOL
637 B
Text
# Exploit Title: PictureTrail Photo Editor GE.exe 2.00 - ./bmp Crash PoC
|
|
# Date: 01-03-2016
|
|
# Exploit Author: redknight99
|
|
# Vendor Homepage: http://www.picturetrail.com/
|
|
# Software Link: http://www.picturetrail.com/downloads/photoeditor200.exe
|
|
# Version: 2.0.0
|
|
# Tested on: Windows 7, 10
|
|
# CVE : Unknown
|
|
|
|
Picture Trail Photo editor fails to properly parse .bmp header height and width values.
|
|
Negative height and width values cause a program crash (memory corruption) and SEH corruption. Remote code execution may be possible.
|
|
|
|
|
|
Proof of Concept:
|
|
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39518.zip |