Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)
Vulnerability Description
Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters that allows attackers to execute arbitrary code. Attackers can craft malicious payloads and overwrite Structured Exception Handler (SEH) to execute shellcode when pasting specially crafted input into the application's input fields.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37013
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Felipe Winsnes
References
- https://www.exploit-db.com/exploits/48796
- https://web.archive.org/web/20210105222148/https://whitecr0wz.github.io/assets/img/Findings11/11-proof.gif
- https://archive.org/details/tucows_288670_Audio_Playback_Recorder
- https://www.vulncheck.com/advisories/audio-playback-recorder-local-buffer-overflow-seh
Affected Vendor
Tucows Inc.
View all reports →