vendor:
AyeView
by:
suN8Hclf (DaRk-CodeRs Group), crimson.loyd@gmail.com
7.5
CVSS
HIGH
Denial of Service (DoS)
CWE
Product Name: AyeView
Affected Version From: v2.20
Affected Version To: v2.20
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
AyeView v2.20 (invalid bitmap header parsing) DoS Exploit
AyeView v2.20 software does not properly parse values in bmp file header, allowing an attacker to create a special bitmap that can slow down or suspend the entire system. The exploit triggers AyeView to allocate large amounts of memory, causing the system to slow down or crash.