vendor:
Duplicate Cleaner Pro
by:
Achilles
5.5
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: Duplicate Cleaner Pro
Affected Version From: 4.1.2003
Affected Version To: 4.1.2003
Patch Exists: NO
Related CWE:
CPE: a:digital_volcano:duplicate_cleaner_pro:4.1.3
Platforms Tested: Windows 7 x64
2020
Duplicate Cleaner Pro 4 – Denial of Service (PoC)
The exploit creates a large buffer filled with 'A' characters and attempts to write it to a file named 'Evil.txt'. If successful, the exploit will cause the Duplicate Cleaner Pro software to crash when the content of 'Evil.txt' is pasted into the 'License key' field and the 'Activate' button is clicked.
Mitigation:
Update to a patched version of Duplicate Cleaner Pro that addresses the buffer overflow vulnerability.