vendor:
Edraw Flowchart ActiveX Control
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: Edraw Flowchart ActiveX Control
Affected Version From: 2.3
Affected Version To: 2.3.0.6
Patch Exists: NO
Related CWE:
CPE: a:edrawsoft:edraw_flowchart_activex_control:2.3
Platforms Tested: Windows XP Professional SP3
2010
EDraw Flowchart ActiveX Control 2.3 (.edd parsing) Remote Buffer Overflow PoC
EDraw Flowchart ActiveX Control version 2.3 suffers from a buffer overflow vulnerability when parsing .edd file format resulting in an application crash and overwritten few memory registers which can aid the attacker to execute arbitrary code.
Mitigation:
Apply the latest patch or update to a version that is not affected by this vulnerability.