vendor:
WM Recorder 16.8.1
by:
bzyo
7.8
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: WM Recorder 16.8.1
Affected Version From: 16.8.1
Affected Version To: 16.8.1
Patch Exists: YES
Related CWE: N/A
CPE: a:wm_recorder:wm_recorder:16.8.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x86/x64, Windows 10 x64
2018
WM Recorder 16.8.1 – Denial of Service
WM Recorder 16.8.1 is vulnerable to a denial of service attack. An attacker can generate a crash.txt file containing a buffer of 429 A characters, 4 B characters, 4 C characters, and 9562 D characters. The attacker can then open the application, go to Schedule Recordings, Open Scheduler, paste the contents of the crash.txt file in Stream URL, File name and Website URL, change End Recording date to future date, turn scheduler on, and select OK. This will cause the application to crash and overwrite the EIP register.
Mitigation:
Update to the latest version of WM Recorder 16.8.1