vendor:
Beatcraft
by:
Koshi
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Beatcraft
Affected Version From: v1.02 Build 19
Affected Version To: v1.02 Build 19
Patch Exists: YES
Related CWE: N/A
CPE: a:acoustica:beatcraft
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2008
Acoustica Beatcraft (bcproj file) Local BOF Exploit
Acoustica Beatcraft contains a buffer prone to exploitation via an overly long string. The buffer contains the 'title' of the 'instruments' one can insert into a Beatcraft project. This exploit is a bit unstable in the fact that, to properly exploit it, one must open Beatcraft firstly, then proceed to open the exploit file from within Beatcraft. Simply double clicking the file will result in a simple DoS scenario.
Mitigation:
Update to the latest version of Acoustica Beatcraft