vendor:
Aida64 Engineer
by:
Nipun Jaswal
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Aida64 Engineer
Affected Version From: 6.00.5100
Affected Version To: 6.00.5100
Patch Exists: NO
Related CWE: CVE-2019-XXXX
CPE: a:aida64:engineer:6.00.5100
Platforms Tested: Windows 7 Home Basic(x86)
2019
Aida64 6.00.5100 ‘Log to CSV File’ Local SEH Buffer Overflow Exploit
This exploit takes advantage of a buffer overflow vulnerability in Aida64 version 6.00.5100. By pasting specific content into the 'Log Sensor Reading to CSV log File' field in the application, an attacker can trigger a SEH buffer overflow.
Mitigation:
Update to a patched version of Aida64.