CVE-2018-25284
MEDIUMHD Tune Pro 5.70 Denial of Service via Options Dialog
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25284. PoCs published by Gionathan Reale.
AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in HD Tune Pro 5.70 by creating a maliciously crafted file with a large buffer of 'A' characters. When the file content is pasted into the 'Folder / file name' field in the application's options, it triggers a crash due to buffer overflow.
Description
HD Tune Pro 5.70 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the folder/file name field. Attackers can trigger a denial of service by entering a 6000-byte payload through the File > Options > Save dialog's folder/file name input field.
Exploits (1)
This exploit demonstrates a Denial of Service (DoS) vulnerability in HD Tune Pro 5.70 by creating a maliciously crafted file with a large buffer of 'A' characters. When the file content is pasted into the 'Folder / file name' field in the application's options, it triggers a crash due to buffer overflow.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H