vendor:
Macro Express Pro
by:
Unknown
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Macro Express Pro
Affected Version From: 4.2.2.1
Affected Version To: 4.2.1.1
Patch Exists: NO
Related CWE: N/A
CPE: a:insight_software_solutions:macro_express_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2009
Macro Express Pro 4.2.2.1 MXE File Syntactic Analysis Buffer Overflow PoC
Macro Express Pro suffers from a buffer overflow vulnerability when importing playable macro files (.mxe) with added large amount of bytes into the elements: string, integer, float and control. The user input is not properly sanitized which may give the attackers the possibility for an arbitrary code execution on the affected system. Failure of exploitation may result in a denial of service.
Mitigation:
Input validation should be used to prevent the exploitation of this vulnerability.