vendor:
Iperius Backup
by:
bzyo
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Iperius Backup
Affected Version From: 5.8.1
Affected Version To: 5.8.1
Patch Exists: YES
Related CWE: N/A
CPE: a:iperius_software:iperius_backup
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1 x86
2018
Iperius Backup 5.8.1 – Buffer Overflow (SEH)
Iperius Backup 5.8.1 is vulnerable to a buffer overflow vulnerability when a maliciously crafted file is opened. This can be exploited to execute arbitrary code by causing a stack-based buffer overflow via a specially crafted file. The vulnerability is due to a lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of Iperius Backup 5.8.1 or later.