vendor:
TwistedBrush Pro Studio
by:
Alejandra Sánchez
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: TwistedBrush Pro Studio
Affected Version From: 24.06
Affected Version To: 24.06
Patch Exists: YES
Related CWE: N/A
CPE: a:pixarra:twistedbrush_pro_studio
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
TwistedBrush Pro Studio 24.06 – ‘Script Recorder’ Denial of Service (PoC)
TwistedBrush Pro Studio 24.06 is vulnerable to a denial of service attack when a specially crafted file is opened in the 'Script Recorder' feature. An attacker can create a file containing 500000 'A' characters and paste it into the 'Description' field of the 'Script Recorder' feature, which will cause the application to crash.
Mitigation:
Upgrade to the latest version of TwistedBrush Pro Studio.