vendor:
XnConvert
by:
Gokkulraj (TwinTech Solutions)
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: XnConvert
Affected Version From: 1.82
Affected Version To: 1.82
Patch Exists: NO
Related CWE: N/A
CPE: a:xnview:xnconvert
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64
2019
XnConvert 1.82 – Denial of Service (PoC)
XnConvert is vulnerable to Denial of Service attack. An attacker can create a malicious file with 9000 'A' characters and paste the content of the file into the 'User Name and Registration Code' field of XnConvert. This will cause the application to crash.
Mitigation:
The user should not open any malicious files or paste any malicious content into the application.