vendor:
FlashFXP
by:
Paras Bhatia
7.5
CVSS
HIGH
Denial of Service (DoS) Local
CWE
Product Name: FlashFXP
Affected Version From: 4.2.0 Build 1730
Affected Version To: 4.2.0 Build 1730
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro (64 bit)
2020
FlashFXP 4.2.0 Build 1730 – Denial of Service (PoC)
The exploit allows an attacker to cause a denial of service (DoS) by crashing the FlashFXP software. By providing a specially crafted input, the software crashes when attempting to process it, rendering it unresponsive and unavailable.
Mitigation:
Update FlashFXP software to a non-vulnerable version or apply any patches released by the vendor.