UltraISO 9.7.1.3519 Buffer Overflow via Output FileName
Vulnerability Description
UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite values and paste it into the Output FileName field to trigger a denial of service crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25267
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Francisco Ramirez
Affected Vendor
Ultraiso
View all reports →