vendor:
Allok Video to DVD Burner
by:
T3jv1l
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Allok Video to DVD Burner
Affected Version From: Allok Video to DVD Burner 2.6.1217
Affected Version To: Allok Video to DVD Burner 2.6.1217
Patch Exists: NO
Related CWE:
CPE: a:alloksoft:allok_video_to_dvd_burner:2.6.1217
Platforms Tested: Windows 7 SP1 x86
2018
Buffer Overflow(SEH) on Allok Video to DVD Burner2.6.1217
The exploit code creates a file called 'Evil.txt' and copies its content into the License Name field of the Allok Video to DVD Burner software. This triggers a buffer overflow vulnerability in the software, allowing the attacker to execute arbitrary code.
Mitigation:
Apply the latest patch or update from the vendor.