vendor:
CloudMe Sync
by:
hyp3rlinx, Daniel Teixeira
9.8
CVSS
CRITICAL
Stack-based Buffer Overflow
119
CWE
Product Name: CloudMe Sync
Affected Version From: 1.10.2009
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: CVE-2018-6892
CPE: Not mentioned
Platforms Tested: Windows 7 SP1 x86
Not mentioned
CloudMe Sync v1.10.9
This module exploits a stack-based buffer overflow vulnerability in CloudMe Sync v1.10.9 client application. The vulnerability allows an attacker to execute arbitrary code by sending a specially crafted buffer to the vulnerable application. This module has been tested successfully on Windows 7 SP1 x86.
Mitigation:
The vendor has released a patch for this vulnerability. Users are advised to update to the latest version of CloudMe Sync to mitigate the risk.