Ether MP3 CD Burner
cpe:2.3:a:ether_software:mp3/avi/mpeg/wmv/rm_to_audio_cd_burner:*:*:*:*:*:*:*
- 1.3.8
A buffer overflow vulnerability has been identified in Ether MP3 CD Burner version 1.3.8. The issue resides in the registration name field, where improper input validation allows attackers to craft malicious payloads that overwrite Structured Exception Handling (SEH) handlers. This exploitation can lead to remote code execution, with the possibility of executing a bind shell on port 3110.
Exploitation of this vulnerability allows for remote code execution on the affected system.
The vulnerability can be reproduced by using a Python script to create a payload that exploits the buffer overflow. This payload should be saved into a text file, which is then copied to the clipboard. After opening the Ether MP3 CD Burner application and pasting the payload into the registration field, clicking 'OK' will trigger the exploit. A bind shell can then be accessed on port 3110.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.