vendor:
BlazeDVD Pro
by:
Giovanni Bartolomucci
7.5
CVSS
HIGH
Stack Based Buffer Overflow
119
CWE
Product Name: BlazeDVD Pro
Affected Version From: 7.0.0.0
Affected Version To: 7.0.0.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 8.1 Pro
2014
BlazeDVD Pro v7.0 – (.plf) Stack Based Buffer Overflow (direct RET) – ALSR/DEP bypass on Win8.1 Pro
This exploit takes advantage of a stack based buffer overflow vulnerability in BlazeDVD Pro v7.0. By sending a specially crafted .plf file, an attacker can overwrite the return address and gain control of the program flow. This exploit bypasses ALSR and DEP protections on Windows 8.1 Pro.
Mitigation:
Update to a patched version of BlazeDVD Pro that addresses the buffer overflow vulnerability.