vendor:
MyVideoConverter Pro
by:
ZwX
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: MyVideoConverter Pro
Affected Version From: 3.14
Affected Version To: 3.14
Patch Exists: NO
Related CWE:
CPE: a:myvideoconverter_pro:myvideoconverter_pro:3.14
Platforms Tested: Windows 10 v1803
2020
MyVideoConverter Pro 3.14 – ‘Movie’ Buffer Overflow
The exploit script creates a new file with the name 'Shell.txt' and copies the content inside. Then, when the program is started and the 'Movie' option is selected, the content of 'Shell.txt' is pasted into the 'Video Folder' field, resulting in the execution of the calculator.
Mitigation:
Update to a patched version of MyVideoConverter Pro.