vendor:
LabelPrint
by:
modpr0be, f3ci
7.8
CVSS
HIGH
Stack Buffer Overflow
Buffer Overflow
CWE
Product Name: LabelPrint
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: NO
Related CWE: CVE-2017-14627
CPE: a:cyberlink:labelprint:2.5
Platforms Tested: Windows
2017
CyberLink LabelPrint 2.5 Stack Buffer Overflow
This module exploits a stack buffer overflow in CyberLink LabelPrint 2.5 and below. The vulnerability is triggered when opening a .lpp project file containing overly long string characters via open file menu. This results in overwriting a structured exception handler record and take over the application. This module has been tested on Windows 7 (64 bit), Windows 8.1 (64 bit), and Windows 10 (64 bit).
Mitigation:
Update to the latest version of CyberLink LabelPrint.