CVE-2013-6079
MostGear Soft Easy LAN Folder Share 3.2.0.100 - Buffer Overflow via Long Registration Code or License Registry Key
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2013-6079. PoCs published by sagi-, ariarat.
AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in Easy LAN Folder Share 3.2.0.100 via a malicious registry file. It uses SEH overwrite with a jump to shellcode that executes calc.exe.
Description
Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in the (1) registration code field in the activate license window or the (2) HKLM\SOFTWARE\MostGear\EasyLanFolderShare_V1\License registry key. NOTE: it is not clear from the original report whether this issue crosses privilege boundaries. If not, then it should not be included in CVE.
Exploits (2)
This exploit leverages a buffer overflow vulnerability in Easy LAN Folder Share 3.2.0.100 via a malicious registry file. It uses SEH overwrite with a jump to shellcode that executes calc.exe.
This exploit demonstrates a buffer overflow vulnerability in Easy LAN Folder Share 3.2.0.100 by generating a 1000-byte string of 'A' characters. The payload is designed to trigger an SEH overwrite when pasted into the 'Registration Code' field during activation.