vendor:
YouTube Video Grabber
by:
Achilles
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: YouTube Video Grabber
Affected Version From: 1.9.9.1
Affected Version To: 1.9.9.1
Patch Exists: NO
Related CWE:
CPE: a:litexmedia:youtube_video_grabber:1.9.9.1
Platforms Tested: Windows 7 64bit
2021
YouTube Video Grabber 1.9.9.1 – Buffer Overflow (SEH)
This exploit takes advantage of a buffer overflow vulnerability in YouTube Video Grabber version 1.9.9.1. By running a Python code, an attacker can trigger the overflow and gain control over the program. The exploit involves opening a malicious file, which leads to the execution of arbitrary code and the creation of a bind shell on port 3110.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users are advised to avoid opening untrusted files or using outdated versions of the software.