CVE-2012-10051

HIGH

Photodex ProShow Producer <5.0.3256 - Buffer Overflow

Title source: llm

Description

Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugin load list files. When a specially crafted load file is placed in the installation directory, the application fails to properly validate its contents, leading to a buffer overflow when the file is parsed during startup. Exploitation requires local access to place the file and user interaction to launch the application.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/20109
exploitdb WORKING POC VERIFIED
by Julien Ahrens · textdoswindows
https://www.exploit-db.com/exploits/19563
metasploit WORKING POC NORMAL
by Julien Ahrens, mr.pr0n, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/proshow_load_bof.rb

Scores

CVSS v4 8.4
EPSS 0.0824
EPSS Percentile 92.2%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
Photodex Corporation/ProShow Producer 5.0.3256
Published Aug 08, 2025
Tracked Since Feb 18, 2026