NCTSoft NCTVideoStudio ActiveX Control 'CreateFile()' Heap Buffer Overflow Vulnerability
BID:33469
Info
NCTSoft NCTVideoStudio ActiveX Control 'CreateFile()' Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 33469 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2009 12:00AM |
| Updated: | Jan 28 2009 07:09PM |
| Credit: | Mountassif Mouad (Stack) |
| Vulnerable: |
NCTsoft NCTVideoStudio 1.6 |
| Not Vulnerable: | |
Discussion
NCTSoft NCTVideoStudio ActiveX Control 'CreateFile()' Heap Buffer Overflow Vulnerability
NCTSoft NCTVideoStudio ActiveX control is prone to a heap-based buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
NCTVideoStudio 1.6 is vulnerable; other versions may also be affected.
NCTSoft NCTVideoStudio ActiveX control is prone to a heap-based buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
NCTVideoStudio 1.6 is vulnerable; other versions may also be affected.
Exploit / POC
NCTSoft NCTVideoStudio ActiveX Control 'CreateFile()' Heap Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
NCTSoft NCTVideoStudio ActiveX Control 'CreateFile()' Heap Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NCTSoft NCTVideoStudio ActiveX Control 'CreateFile()' Heap Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (NCTSoft)