vendor:
Backup Key Recovery
by:
Ismail Tasdelen
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: Backup Key Recovery
Affected Version From: 2.2.2005
Affected Version To: 2.2.2005
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2020
Backup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 – ‘Key’ Denial of Service (PoC)
This exploit allows an attacker to crash the Backup Key Recovery software by providing a specially crafted 'Key' value. By running a python script, a file (poc.txt) is created with a payload of 1000 'A' characters. When the software is launched and the payload is copied into the 'Key' field, the software crashes.
Mitigation:
The vendor should release a patch or update to fix the software crash when handling the specially crafted 'Key' value.