vendor:
Wedding Slideshow Studio
by:
ZwX
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Wedding Slideshow Studio
Affected Version From: 1.36
Affected Version To: 1.36
Patch Exists: YES
Related CWE: N/A
CPE: a:wedding_slideshow_studio:wedding_slideshow_studio
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 v1803
2020
Wedding Slideshow Studio 1.36 – ‘Name’ Buffer Overflow
A buffer overflow vulnerability exists in Wedding Slideshow Studio 1.36 when a long string is entered into the 'Registration Name' field. An attacker can exploit this vulnerability by running a python exploit script which will create a new file with the name 'name.txt'. The attacker can then copy the text inside 'name.txt' and paste it into the 'Registration Name' field. This will cause a buffer overflow and allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to the latest version of Wedding Slideshow Studio.