vendor:
NCTAudioStudio2
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
CWE
Product Name: NCTAudioStudio2
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
NCTAudioStudio2 ActiveX DLL (NCTWavChunksEditor2.dll v. 2.6.1.148) “CreateFile()” Insecure Method
The exploit overwrites the system.ini file, potentially causing damage to the system. It is recommended to make a copy of the file before running the exploit.
Mitigation:
Make a backup of the system.ini file before running the exploit.