Download Accelerator Plus Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in Download Accelerator Plus (DAP) version 10.0.6.0. This vulnerability involves a structured exception handler (SEH) buffer overflow that enables remote attackers to execute arbitrary code. Exploitation is achieved by crafting malicious URLs that contain overflowing buffer data, which overwrites SEH pointers and executes embedded shellcode. The vulnerability is triggered when these URLs are imported through the application's web page import functionality.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Reproduction

To reproduce this vulnerability, first create a payload that includes the overflow data, SEH overwrite, and the shellcode (such as a payload to open the calculator). This can be done using a Python script that generates a text file containing the crafted URL payload. Once the payload is prepared, open Download Accelerator Plus and use the 'Import' feature to load the URL containing the malicious payload. The application will execute the embedded shellcode, demonstrating the successful exploitation of the vulnerability.

Added: Mar 24, 2026, 12:43 PM
Updated: Mar 24, 2026, 12:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.0
remediation
0.0
relevance
4.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.