vendor:
Free MP3 CD Ripper
by:
Matteo Malvica
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Free MP3 CD Ripper
Affected Version From: 2.8
Affected Version To: 2.8
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 - 64bit
2018
Free MP3 CD Ripper 2.8 – ‘.wma’ Buffer Overflow (SEH) (DEP Bypass)
This exploit takes advantage of a buffer overflow vulnerability in Free MP3 CD Ripper version 2.8. By creating a specially crafted '.wma' file and loading it into the program, an attacker can execute arbitrary code with the privileges of the user running the program. The exploit bypasses Data Execution Prevention (DEP) and uses a modified Structured Exception Handler (SEH) exploit. Upon successful exploitation, a calculator application will be launched on the victim's machine.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid loading untrusted '.wma' files into the Free MP3 CD Ripper program.