vendor:
AIDA64 Extreme
by:
Peyman Forouzan
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: AIDA64 Extreme
Affected Version From: 5.99.4900
Affected Version To: 5.99.4900
Patch Exists: Yes
Related CWE: N/A
CPE: a:finalwire:aida64_extreme:5.99.4900
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Winxp SP2 32-64 bit - Win7 Enterprise SP1 32-64 bit - Win10 Enterprise 32-64 bit
2019
AIDA64 Extreme 5.99.4900 – Logging SEH Buffer Overflow
AIDA64 Extreme 5.99.4900 is vulnerable to a SEH buffer overflow vulnerability. An attacker can exploit this vulnerability by running a specially crafted python code which creates two files. The attacker then needs to paste the contents of either exploit-x32.txt or exploit-x64.txt (depending on the Windows version) into the Log sensor reading to CSV log file field in the Preferences menu. When the attacker exits the program, the shellcode (calc) will be opened.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of AIDA64 Extreme.