vendor:
Easy RM to MP3 Converter
by:
Felipe Winsnes
7.5
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: Easy RM to MP3 Converter
Affected Version From: 2.7.3.700
Affected Version To: 2.7.3.700
Patch Exists: NO
Related CWE:
CPE: a:easy_rm_to_mp3_converter:easy_rm_to_mp3_converter:2.7.3.700
Platforms Tested: Windows 7 (x86)
2020
Easy RM to MP3 Converter 2.7.3.700 – ‘Input’ Local Buffer Overflow (SEH)
This exploit takes advantage of a local buffer overflow vulnerability in Easy RM to MP3 Converter version 2.7.3.700. By running a Python script and copying the generated content to the clipboard, an attacker can trigger the overflow when pasting the content into the 'Input' parameter of the application. This allows the attacker to execute arbitrary code and potentially gain control of the affected system.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users are advised to avoid using the Easy RM to MP3 Converter version 2.7.3.700 or to use alternative software.