vendor:
UltraISO
by:
Dino Covotsos - Telspace Systems
7.5
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: UltraISO
Affected Version From: 9.7.1.3519
Affected Version To: 9.7.1.3519
Patch Exists: NO
Related CWE: CVE-TBC
CPE: a:ultraiso:ultraiso:9.7.1.3519
Platforms Tested: Windows XP Prof SP3 ENG x86
2019
UltraISO 9.7.1.3519 – Local Buffer Overflow (SEH)
This exploit takes advantage of a local buffer overflow vulnerability in UltraISO version 9.7.1.3519. By generating a specially crafted exploit.txt file and pasting its contents under 'Output FileName' in the application, an attacker can execute arbitrary code on the target system.
Mitigation:
Update UltraISO to a patched version.