vendor:
UltraISO
by:
Francisco Ramirez
7.8
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: UltraISO
Affected Version From: 9.7.1.3519
Affected Version To: 9.7.1.3519
Patch Exists: YES
Related CWE: N/A
CPE: a:ezbsystems:ultraiso:9.7.1.3519
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro - 64 bit
2018
UltraISO 9.7.1.3519 – ‘Output FileName’ Denial of Service (PoC) and Pointer to next SEH and SE handler records overwrite
UltraISO 9.7.1.3519 is vulnerable to a denial of service attack when a maliciously crafted file is opened. An attacker can exploit this vulnerability by creating a specially crafted file and then convincing a user to open it. This will cause a denial of service condition.
Mitigation:
Upgrade to the latest version of UltraISO 9.7.1.3519 or later.