Uderzo Software SpaceSniffer Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in Uderzo Software SpaceSniffer version 2.0.5.18. This vulnerability allows remote attackers to execute arbitrary code by exploiting a crafted .sns snapshot file. The issue arises because SpaceSniffer parses these files using an attacker-controlled length value, which is improperly validated, leading to stack-based memory corruption.

Impact

Exploitation of this vulnerability causes stack memory corruption, crashes the application, and can be leveraged for arbitrary code execution in the context of the user running SpaceSniffer.

Reproduction

To reproduce this vulnerability, a remote attacker can create a .sns file with an oversized length value that causes a stack overflow during parsing. This file can then be delivered to the victim through email, chat, or download. Once the file is opened in SpaceSniffer, the application will crash, and the code execution can be observed, such as through a benign MessageBoxW call.

Remediation

This vulnerability has been resolved in SpaceSniffer version 2.1.0.21.

Added: Mar 10, 2026, 7:05 PM
Updated: Mar 10, 2026, 7:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.0
remediation
0.0
relevance
3.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.