SocuSoft DVD Photo Slideshow Professional Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in SocuSoft DVD Photo Slideshow Professional version 8.07. The issue resides in the registration name field, where local attackers can exploit structured exception handling to execute arbitrary code. By crafting a malicious text file with a payload that includes junk bytes, an overwrite of the SEH chain, and shellcode, attackers can paste this content into the Registration Name field via the Help > Register menu, triggering the execution of the injected code.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Reproduction

To reproduce this vulnerability, create a text file containing a payload with junk bytes, an overwrite of the structured exception handling (SEH) chain, and shellcode. Then, paste this crafted payload into the Registration Name field through the Help > Register option. The application will execute the injected code, demonstrating the buffer overflow vulnerability.

Added: May 26, 2026, 7:32 PM
Updated: May 26, 2026, 7:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.0
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.