vendor:
Lavavo CD Ripper
by:
Achilles
7.5
CVSS
HIGH
Local SEH Overflow
119
CWE
Product Name: Lavavo CD Ripper
Affected Version From: 4.2
Affected Version To: 4.2
Patch Exists: NO
Related CWE:
CPE: a:lavavo_software:lavavo_cd_ripper:4.20
Platforms Tested: Windows XP SP3 EN, Windows 7 Sp1 x64
2019
Lavavo CD Ripper 4.20 Local Seh Exploit
This exploit targets a local SEH (Structured Exception Handling) overflow vulnerability in Lavavo CD Ripper version 4.20. By providing a specially crafted 'License Activation Name' value, an attacker can trigger a buffer overflow and execute arbitrary code. This exploit creates a bind shell on port 3110.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid using the affected version of Lavavo CD Ripper.