vendor:
AnyBurn
by:
Richard Davy/Gary Nield
7.8
CVSS
HIGH
Buffer Overflow/SEH/Unicode
119
CWE
Product Name: AnyBurn
Affected Version From: 4.8
Affected Version To: 4.8
Patch Exists: YES
Related CWE: N/A
CPE: a:anyburn:anyburn:4.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Enterprise x64
2020
AnyBurn 4.8 – Buffer Overflow (SEH)
A buffer overflow vulnerability in AnyBurn 4.8 allows an attacker to execute arbitrary code by sending a specially crafted payload to the application. The vulnerability is due to improper bounds checking of user-supplied input, which can be exploited to cause a stack-based buffer overflow. This can be exploited to execute arbitrary code by overwriting the structured exception handler (SEH) with a custom handler.
Mitigation:
Upgrade to the latest version of AnyBurn.