vendor:
Hex Workshop
by:
DATA_SNIPER
7,8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Hex Workshop
Affected Version From: 3.11
Affected Version To: 6.00
Patch Exists: YES
Related CWE: CVE-2009-0478
CPE: a:bpsoft:hex_workshop
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Hex Workshop v3//4//5//6 (.hex) Universal Local Buffer ExploitS (SEH)
Hex Workshop is a hexadecimal editor that allows users to edit binary files. A buffer overflow vulnerability exists in Hex Workshop versions 3, 4, 5, and 6. An attacker can exploit this vulnerability by sending a specially crafted .hex file to the victim, which can lead to arbitrary code execution. The vulnerability is due to insufficient bounds checking when processing the .hex file.
Mitigation:
Upgrade to the latest version of Hex Workshop.