Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50922. PoCs published by Hejap Zairy Al-Sharif.
AI-analyzed exploit summary This exploit leverages a buffer overflow in Audio Conversion Wizard v2.01 by overwriting the EIP with a 'push esp' instruction from id3lib.dll, followed by a reverse shell payload generated via msfvenom. The payload is delivered through a maliciously crafted text file pasted into the software's 'Enter Code' field.
Description
Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.
Exploits (1)
This exploit leverages a buffer overflow in Audio Conversion Wizard v2.01 by overwriting the EIP with a 'push esp' instruction from id3lib.dll, followed by a reverse shell payload generated via msfvenom. The payload is delivered through a maliciously crafted text file pasted into the software's 'Enter Code' field.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H