vendor:
Ultra ISO
by:
Thomas Pollet
7.5
CVSS
HIGH
Code Execution
CWE
Product Name: Ultra ISO
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Ultra ISO Exploit
The exploit allows an attacker to execute arbitrary code by creating a malicious CUE file that triggers a buffer overflow vulnerability in Ultra ISO. This can be used to run arbitrary shellcode, such as the Metasploit calc.exe shellcode used in this example.
Mitigation:
Update to a patched version of Ultra ISO or use an alternative software. Avoid opening CUE files from untrusted sources.