Advisories

Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)

Go Back
severity
none
date
Affecting
  • Frigate Professional 3.36.0.9

CWE
  • CWE-121 Stack-based Buffer Overflow
CVSS
0
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
MasterVlad
Description
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.