vendor:
UltraISO
by:
Ali Alipour
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: UltraISO
Affected Version From: 9.7.1.3519
Affected Version To: 9.7.1.3519
Patch Exists: YES
Related CWE: N/A
CPE: a:ezbsystems:ultraiso
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 - 64-bit
2018
UltraISO 9.7.1.3519 – Denial Of Service (PoC)
UltraISO is vulnerable to a Denial of Service attack when a maliciously crafted file is opened. An attacker can exploit this vulnerability by creating a file with a large number of 'A' characters and then opening it in UltraISO. This will cause the application to crash.
Mitigation:
Users should avoid opening files from untrusted sources. Additionally, users should ensure that they are running the latest version of UltraISO.