vendor:
SyncBreeze
by:
Filipe Oliveira, Rafael Machado
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SyncBreeze
Affected Version From: 10.1.16
Affected Version To: 10.1.16
Patch Exists: YES
Related CWE: CVE-2017-15950
CPE: a:syncbreeze:syncbreeze:10.1.16
Platforms Tested: Windows 10 x64
2021
SyncBreeze 10.1.16 – XML Parsing Stack-based Buffer Overflow
The exploit allows an attacker to execute arbitrary code by exploiting a stack-based buffer overflow vulnerability in SyncBreeze. By crafting a specially crafted XML file and importing it into the application, the attacker can trigger the overflow and gain control over the program.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of SyncBreeze to mitigate the risk.