Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://cwe.mitre.org/data/definitions/121.html | third party advisory |
https://www.vulnerability-lab.com/get_content.php?id=2236 | third party advisory exploit |