vendor:
FileOptimizer
by:
Chase Hatch (SYANiDE)
0.0
CVSS
LOW
Denial of Service
20
CWE
Product Name: FileOptimizer
Affected Version From: 14.00.2524
Affected Version To: 14.00.2524
Patch Exists: NO
Related CWE: none
CPE: a:nikkhokkho:fileoptimizer:14.00.2524
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Ultimate x86 SP0
2019
FileOptimizer 14.00.2524 – Denial of Service (PoC)
FileOptimizer 14.00.2524 is vulnerable to a denial of service attack. An attacker can create a malicious configuration file with a large buffer of characters, which when opened by the application will cause it to crash. This can be done by replacing the “TempDirectory” variable in the “FileOptimizer32.ini” file with a large buffer of characters.
Mitigation:
Ensure that the application is configured to only accept valid input and reject any malicious input.