vendor:
AIDA64 Business Edition
by:
Peyman Forouzan
7.8
CVSS
HIGH
SEH Buffer Overflow
119
CWE
Product Name: AIDA64 Business Edition
Affected Version From: 5.99.4900
Affected Version To: 5.99.4900
Patch Exists: YES
Related CWE: N/A
CPE: a:finalwire:aida64_business_edition
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WinXP SP2 32-64 bit, Win7 Enterprise SP1 32-64 bit, Win10 Enterprise 32-64 bit
2019
AIDA64 Business 5.99.4900 – SEH Buffer Overflow (EggHunter)
The program has SEH Buffer Overflow in several places. This code shows one of them. To optimize code, a 'stack pivot' has been used that is the same in Extreme, Engineer, and Network Audit Editions. All the old versions of the program that are available on the sites like soft32.com, or in https://www.aida64.com/downloads/archive have the same vulnerability in different offsets. This technique (EggHunter) has been used to find the exact address of the shellcode.
Mitigation:
Apply the latest security patches and updates to the affected software.