CVE-2013-5582
HIGHAmmyy Admin < 3.2 - Improper Authentication via Fixed Memory Location
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-5582. PoCs published by Bhadresh Patel.
AI-analyzed exploit summary The exploit demonstrates a hidden hard-coded option ('-nogui') and an access control vulnerability in Ammyy Admin, allowing an attacker to use it as a trojan horse by reading the client ID from a fixed memory location (004A3658). The PoC includes AutoIt code to interact with process memory and hijack the client ID.
Description
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.
Exploits (1)
The exploit demonstrates a hidden hard-coded option ('-nogui') and an access control vulnerability in Ammyy Admin, allowing an attacker to use it as a trojan horse by reading the client ID from a fixed memory location (004A3658). The PoC includes AutoIt code to interact with process memory and hijack the client ID.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H