vendor:
Code Blocks
by:
Paras Bhatia
7.2
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: Code Blocks
Affected Version From: 17.12
Affected Version To: 17.12
Patch Exists: NO
Related CWE: N/A
CPE: a:codeblocks:codeblocks:17.12
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Ultimate Service Pack 1 (32 bit - English)
2020
Code Blocks 17.12 – ‘File Name’ Local Buffer Overflow (Unicode) (SEH) (PoC)
Code Blocks 17.12 is vulnerable to a local buffer overflow vulnerability when a user pastes a specially crafted string into the 'Filename with fullpath' field. This can be exploited to execute arbitrary code by a local attacker.
Mitigation:
The user should not open any untrusted files or applications.