CVE-2017-6953
HIGHGemalto SmartDiag Diagnosis Tool v2.5 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6953. PoCs published by Majid Alqabandi.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Gemalto SmartDiag Diagnosis Tool v2.5, leading to SEH overwrite and arbitrary code execution. The PoC includes a payload designed to create a backdoor on port 31337.
Description
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted input to SmartDiag.exe or SymDiag.exe.
Exploits (1)
This exploit demonstrates a buffer overflow vulnerability in Gemalto SmartDiag Diagnosis Tool v2.5, leading to SEH overwrite and arbitrary code execution. The PoC includes a payload designed to create a backdoor on port 31337.
References (1)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H