Easy MPEG to DVD Burner
cpe:2.3:a:ether_software:easy_mpeg_to_dvd_burner:*:*:*:*:*:*:*
- <= 1.7.11
A local buffer overflow vulnerability has been identified in Easy MPEG to DVD Burner version 1.7.11. This vulnerability arises from improper handling of user input, specifically in the username field, allowing local attackers to execute arbitrary code. By crafting a payload that includes junk data, pointers to the Structured Exception Handling (SEH) chain, and shellcode, attackers can overwrite the SEH handler. This manipulation redirects the program's execution flow, enabling the execution of arbitrary commands, such as launching the calculator application.
Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.
To reproduce this vulnerability, open Easy MPEG to DVD Burner version 1.7.11 and navigate to the registration section. In the username field, paste a payload generated by an exploit script. This payload should include approximately 1008 bytes of junk data, followed by a pointer to the SEH chain, and shellcode designed to execute a command, such as opening calc.exe.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.