CVE-2013-3928

Jpchacha Chasys Draw Ies < 4.10.01 - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/27609
metasploit WORKING POC NORMAL
by Christopher Gabriel, Longinos Recuero Bustos, Javier \, , # PoC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/chasys_draw_ies_bmp_bof.rb

Scores

EPSS 0.7687
EPSS Percentile 99.0%

Details

CWE
CWE-119
Status published
Products (7)
jpchacha/chasys_draw_ies 4.00.01
jpchacha/chasys_draw_ies 4.01.01
jpchacha/chasys_draw_ies 4.02.01
jpchacha/chasys_draw_ies 4.03.02
jpchacha/chasys_draw_ies 4.04.01
jpchacha/chasys_draw_ies 4.06.02
jpchacha/chasys_draw_ies < 4.10.01
Published Mar 11, 2014
Tracked Since Feb 18, 2026