vendor:
WinLicense
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Unspecified Memory Corruption
119
CWE
Product Name: WinLicense
Affected Version From: 2.1.8.0
Affected Version To: 2.1.8.0
Patch Exists: YES
Related CWE: N/A
CPE: a:oreans:winlicense
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN) (32bit), Microsoft Windows 7 Ultimate SP1 (EN) (64bit)
2012
Oreans WinLicense v2.1.8.0 XML File Handling Unspecified Memory Corruption
WinLicense is prone to an unspecified memory corruption vulnerability. An attacker can exploit this issue by tricking a victim into opening a malicious XML file to execute arbitrary code and to cause denial-of-service conditions.
Mitigation:
Update to the latest version of WinLicense