{"api_version":"1","generated_at":"2026-07-23T07:47:04+00:00","cve":"CVE-2017-14627","urls":{"html":"https://cve.report/CVE-2017-14627","api":"https://cve.report/api/cve/CVE-2017-14627.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14627","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14627"},"summary":{"title":"CVE-2017-14627","description":"Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-09-23 20:29:00","updated_at":"2018-12-14 11:29:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/42777/","name":"42777","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.spentera.com/2017/09/19/unicode-stack-based-buffer-overflow-on-cyberlink-labelprint-2-5/","name":"https://blog.spentera.com/2017/09/19/unicode-stack-based-buffer-overflow-on-cyberlink-labelprint-2-5/","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"Unicode Stack-based Buffer Overflow on CyberLink LabelPrint 2.5 – Spentera Blog","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/45985/","name":"45985","refsource":"EXPLOIT-DB","tags":[],"title":"CyberLink LabelPrint 2.5 - Stack Buffer Overflow (Metasploit) - Windows local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14627","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14627","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14627","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cyberlink","cpe5":"labelprint","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"14627","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cyberlink","cpe5":"labelprint","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-14627","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"42777","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/42777/"},{"name":"45985","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/45985/"},{"name":"https://blog.spentera.com/2017/09/19/unicode-stack-based-buffer-overflow-on-cyberlink-labelprint-2-5/","refsource":"MISC","url":"https://blog.spentera.com/2017/09/19/unicode-stack-based-buffer-overflow-on-cyberlink-labelprint-2-5/"}]}},"nvd":{"publishedDate":"2017-09-23 20:29:00","lastModifiedDate":"2018-12-14 11:29:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cyberlink:labelprint:2.5:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14627","Ordinal":"112097","Title":"CVE-2017-14627","CVE":"CVE-2017-14627","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14627","Ordinal":"1","NoteData":"Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"14627","Ordinal":"2","NoteData":"2017-09-23","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14627","Ordinal":"3","NoteData":"2018-12-14","Type":"Other","Title":"Modified"}]}}}