vendor:
Easy CD DVD Copy
by:
Hashim Jawad
7.5
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: Easy CD DVD Copy
Affected Version From: Easy CD DVD Copy v1.3.24
Affected Version To: Easy CD DVD Copy v1.3.24
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP professional SP3, Windows 7 Enterprise SP1, Windows 10 Professional 64bit
Easy CD DVD Copy v1.3.24 – Local Buffer Overflow (SEH)
This exploit allows an attacker to execute arbitrary code by exploiting a buffer overflow vulnerability in Easy CD DVD Copy v1.3.24. The vulnerability occurs when a user pastes a specially crafted content in the 'Enter User Name' field during registration. This allows the attacker to overwrite the Structured Exception Handler (SEH) and gain control of the program execution flow. The exploit includes a payload that launches the Windows calculator (calc.exe) as an example. The vulnerability has been tested on Windows XP professional SP3, Windows 7 Enterprise SP1, and Windows 10 Professional 64bit, with different offset values.
Mitigation:
To mitigate this vulnerability, users are advised to update to a patched version of Easy CD DVD Copy. Additionally, users should exercise caution when copying and pasting content into the software's user interface.