vendor:
Easy Outlook Express Recovery
by:
Ihsan Sencan
7.8
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Easy Outlook Express Recovery
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:munsoft:easy_outlook_express_recovery:2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Easy Outlook Express Recovery 2.0 – Denial of Service (PoC)
A buffer overflow vulnerability exists in Easy Outlook Express Recovery 2.0, which could allow an attacker to cause a denial of service condition. The vulnerability is due to an input validation error when handling a specially crafted registration key. An attacker can exploit this vulnerability by creating a malicious registration key and pasting it into the registration key field. Successful exploitation of this vulnerability could result in a denial of service condition.
Mitigation:
Upgrade to the latest version of Easy Outlook Express Recovery 2.0.