vendor:
Reader
by:
Luigi Auriemma
7.5
CVSS
HIGH
NULL Byte Writing Vulnerability
119
CWE
Product Name: Reader
Affected Version From: 2.1.1.3143
Affected Version To: 2.1.1.3143
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:reader
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Windows Mobile, Tablet PC and UMPC devices
2011
Microsoft Reader <= 2.1.1.3143 (PC version) NULL Byte Writing Vulnerability
Microsoft Reader is a software needed to read and catalog the ebooks in LIT format and the Audible audio books bought via internet. Possibility to write a 0x00 byte in an arbitrary memory location exists due to the lack of check before being written in memory.
Mitigation:
Update to the latest version of Microsoft Reader.