vendor:
AIDA64 Engineer
by:
Hodorsec
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: AIDA64 Engineer
Affected Version From: v6.20.5300
Affected Version To: v6.20.5300
Patch Exists: YES
Related CWE: N/A
CPE: a:aida64:aida64_engineer:6.20.5300
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 x86 SP1 - Build 7601
2020
AIDA64 Engineer 6.20.5300 – ‘Report File’ filename Buffer Overflow (SEH)
Exploits the 'Report File' buffer when sending an e-mail report via the Report wizard. Entering an overly long string, results in a crash which overwrites SEH.
Mitigation:
Ensure that user input is properly validated and sanitized.