vendor:
Anyburn
by:
Hodorsec
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Anyburn
Affected Version From: 4.3
Affected Version To: 4.3
Patch Exists: YES
Related CWE:
CPE: a:anyburn_project:anyburn:4.3
Platforms Tested: Windows 7 SP1
2019
Anyburn 4.3 – ‘Copy disc to image file’ Buffer Overflow – (UNICODE)(SEH)
The exploit allows an attacker to overflow the buffer in the 'Copy disc to image file' function of Anyburn version 4.3. By providing a specially crafted file name, an attacker can execute arbitrary code on the target system. The exploit takes advantage of a buffer overflow vulnerability and uses a unicode mixed shellcode to bypass security measures. The shellcode spawns the Windows calculator application (calc.exe) as a proof of concept.
Mitigation:
The vendor has released a patch for this vulnerability. Users are advised to update to the latest version of Anyburn to mitigate this issue.