Magix Musik Maker <= v16 .mmm Stack-Based Buffer Overflow
Vulnerability Description
Magix Musik Maker 16 is vulnerable to a stack-based buffer overflow due to improper handling of .mmm arrangement files. The vulnerability arises from an unsafe strcpy() operation that fails to validate input length, allowing attackers to overwrite the Structured Exception Handler (SEH). By crafting a malicious .mmm file, an attacker can trigger the overflow when the file is opened, potentially leading to arbitrary code execution. This vulnerability was remediated in version 17.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-10021
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- acidgen
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/magix_musikmaker_16_mmm.rb
- https://www.exploit-db.com/exploits/17329
- https://www.exploit-db.com/exploits/17313
- https://www.magix.com/us/music-editing/music-maker/
- https://www.darkreading.com/vulnerabilities-threats/another-researcher-hit-with-threat-of-german-anti-hacking-law
- https://web.archive.org/web/20110503060356/https://www.corelan.be/index.php/forum/security-advisories/corelan-11-002-magix-music-maker-16-stack-buffer-overflow/
- https://www.vulncheck.com/advisories/magix-musik-maker-stack-based-buffer-overflow
Affected Vendor
MAGIX Software GmbH
View all reports →