Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25604. PoCs published by Kevin Randall.
AI-analyzed exploit summary This exploit demonstrates a local buffer overflow vulnerability in DVDXPlayer 5.5 Pro, leveraging SEH (Structured Exception Handler) overwrite to achieve remote code execution via a crafted .plf file. The payload includes a Meterpreter reverse shell generated with msfvenom.
Description
DVDXPlayer Pro 5.5 contains a local buffer overflow vulnerability with structured exception handling that allows local attackers to execute arbitrary code by crafting malicious playlist files. Attackers can create a specially crafted .plf file containing shellcode and NOP sleds that overflows a buffer and hijacks the SEH chain to execute arbitrary code with application privileges.
Exploits (1)
This exploit demonstrates a local buffer overflow vulnerability in DVDXPlayer 5.5 Pro, leveraging SEH (Structured Exception Handler) overwrite to achieve remote code execution via a crafted .plf file. The payload includes a Meterpreter reverse shell generated with msfvenom.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H