vendor:
AIDA64 Extreme
by:
Peyman Forouzan
7.5
CVSS
HIGH
SEH Buffer Overflow
CWE
Product Name: AIDA64 Extreme
Affected Version From: 5.99.4900
Affected Version To: 5.99.4900
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 32-64 bit, Windows 7 Enterprise SP1 32-64 bit, Windows 10 Enterprise 32-64 bit
2019
AIDA64 Extreme 5.99.4900 – SEH Buffer Overflow (EggHunter)
The program AIDA64 Extreme 5.99.4900 has a SEH Buffer Overflow vulnerability. This code demonstrates one of the instances of the vulnerability. The vulnerability exists in several places within the program. To optimize the code, a stack pivot technique is used, which is the same in Extreme, Engineer, and Network Audit editions of version 5.99.4900. The vulnerability also exists in older versions of the program available on sites like soft32.com or in the AIDA64 downloads archive.
Mitigation:
The vendor should release a patch to fix the SEH Buffer Overflow vulnerability. Users should update to the latest version of AIDA64 Extreme to mitigate the risk.