vendor:
AIDA64 Engineer
by:
Anurag Srivastava and Vardan Bansal
8.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: AIDA64 Engineer
Affected Version From: 5.99.4900
Affected Version To: 5.99.4900
Patch Exists: YES
Related CWE: CVE-2019-10843
CPE: a:aida64:aida64_engineer:5.99.4900
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64
2019
AIDA64 Engineer 5.99.4900 – ‘Load from file’ Field Buffer Overflow (SEH)
A buffer overflow vulnerability exists in AIDA64 Engineer 5.99.4900 when a maliciously crafted 'Load from file' field is processed. An attacker can exploit this vulnerability to execute arbitrary code in the context of the current user.
Mitigation:
Upgrade to the latest version of AIDA64 Engineer