vendor:
STIMS Cutter
by:
Shantanu Khandelwal
7,8
CVSS
HIGH
SEH Overwrite
119
CWE
Product Name: STIMS Cutter
Affected Version From: 1.1.3.20
Affected Version To: 1.1.3.20
Patch Exists: YES
Related CWE: UNKNOWN
CPE: a:stimslabs:stims_cutter
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2016
STIMS CUTTER OVERFLOW SEH OVERWRITE
STIMS Cutter application is vulnerable to SEH Overwrite vulnerability. The vulnerability can be triggered by making a cutt file and opening it in the STIMS Cutter application. When the user clicks on Build Report, the application crashes due to SEH Overwrite.
Mitigation:
The vendor has released a patch to address this vulnerability.