CVE-2013-3928

Chasys Draw IES < 4.11.02 - Remote Code Execution via Crafted BMP File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-3928. PoCs published by Metasploit, Christopher Gabriel, Longinos Recuero Bustos, Javier \, , # PoC, including Metasploit module exploits/windows/fileformat/chasys_draw_ies_bmp_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Chasys Draw IES 4.10.01 by crafting a malicious BMP file. The vulnerability is triggered by manipulating the Width, Planes, and BitCount fields in the BMP header, leading to arbitrary code execution.

Description

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/27609

This Metasploit module exploits a stack-based buffer overflow in Chasys Draw IES 4.10.01 by crafting a malicious BMP file. The vulnerability is triggered by manipulating the Width, Planes, and BitCount fields in the BMP header, leading to arbitrary code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Chasys Draw IES 4.10.01
No auth needed
Prerequisites: Victim must open the malicious BMP file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Christopher Gabriel, Longinos Recuero Bustos, Javier \, , # PoC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/chasys_draw_ies_bmp_bof.rb

This Metasploit module exploits a stack-based buffer overflow in Chasys Draw IES (CVE-2013-3928) by crafting a malicious BMP file. The exploit triggers arbitrary code execution via a JMP ESP instruction in flt_BMP.dll when the file is parsed.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Chasys Draw IES 4.10.01
No auth needed
Prerequisites: Target must open the malicious BMP file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86035
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61463
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/53773
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/27609

Scores

EPSS 0.3708
EPSS Percentile 98.3%

Details

CWE
CWE-119
Status published
Products (7)
jpchacha/chasys_draw_ies 4.00.01
jpchacha/chasys_draw_ies 4.01.01
jpchacha/chasys_draw_ies 4.02.01
jpchacha/chasys_draw_ies 4.03.02
jpchacha/chasys_draw_ies 4.04.01
jpchacha/chasys_draw_ies 4.06.02
jpchacha/chasys_draw_ies < 4.10.01
Published Mar 11, 2014
Tracked Since Feb 18, 2026