vendor:
MASSIVE
by:
Unknown
7,5
CVSS
HIGH
Use-After-Free
416
CWE
Product Name: MASSIVE
Affected Version From: 1.1.4 (R1901)
Affected Version To: 1.1.4 (R1901)
Patch Exists: Unknown
Related CWE: Unknown
CPE: a:native_instruments:massive
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (English)
Unknown
Native Instruments Massive 1.1.4 KSD File Handling Use-After-Free Vulnerability
Massive suffers from a use-after-free error when parsing sound files (.KSD) resulting in a crash. The user input is not properly sanitized which may give the attackers the possibility for an arbitrary code execution on the affected system. Failure of exploitation may result in a denial of service scenario.
Mitigation:
Input validation should be used to prevent the exploitation of this vulnerability.