vendor:
UltraISO
by:
SkD
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: UltraISO
Affected Version From: Unknown
Affected Version To: 9.3.3.2685
Patch Exists: Yes
Related CWE:
CPE: a:ezb_systems:ultraiso
Platforms Tested:
Unknown
UltraISO <= 9.3.3.2685 CCD/IMG Universal Buffer Overflow Exploit
This exploit targets UltraISO version 9.3.3.2685 and allows for a universal buffer overflow. It was discovered and exploited by SkD (skdrat@hotmail.com). The exploit involves opening either a CCD or IMG file in UltraISO. Note that opening the CCD file will also cause an access violation in MagicISO. Private exploits are available for sale by contacting the author at skdrat@hotmail.com. The author holds no responsibility for any damage caused by this exploit.
Mitigation:
Upgrade to a patched version of UltraISO.