Cytel Studio Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A stack-based buffer overflow vulnerability has been identified in Cytel Studio versions through 9.0. This issue arises when the application processes malformed .CY3 files, allowing user-controlled strings to overflow a fixed-size stack buffer of 256 bytes. Exploitation of this vulnerability leads to arbitrary code execution when the crafted file is opened.
Impact
Successful exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Reproduction
The vulnerability can be reproduced by creating a .CY3 file that includes a string payload designed to overflow the stack buffer. This can be done using a Metasploit module specifically developed for this vulnerability, which automates the process of crafting the malicious .CY3 file and exploiting the buffer overflow.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
