vendor:
Free Download Manager
by:
Marwan Shamel
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Free Download Manager
Affected Version From: 2.0 Built 417
Affected Version To: 2.0 Built 417
Patch Exists: YES
Related CWE: N/A
CPE: a:freedownloadmanager:free_download_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Enterprise SP1 32 bit
2018
Free Download Manager 2.0 Built 417 – Local Buffer Overflow (SEH)
Free Download Manager 2.0 Built 417 is vulnerable to a local buffer overflow vulnerability when a malicious URL file is imported. This can be exploited to execute arbitrary code by sending a specially crafted URL file to the application. The vulnerability is due to a lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of Free Download Manager 2.0 Built 417 or later.