vendor:
NCTAudioEditor2
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
264
CWE
Product Name: NCTAudioEditor2
Affected Version From: 2.6.2.157
Affected Version To: 2.6.2.157
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Professional SP2
2007
NCTAudioEditor2 ActiveX DLL (NCTWMAFile2.dll v. 2.6.2.157) “CreateFile()”Insecure Method
This exploit allows an attacker to overwrite the system.ini file, which can cause the system to not restart. It affects all software that use the NCTWMAFile2.dll v. 2.6.2.157 ActiveX DLL, such as Sienzo DMM. It was tested on Windows XP Professional SP2 with Internet Explorer 7.
Mitigation:
Update to the latest version of NCTWMAFile2.dll.