PoC Index

CVE-2017-14627

HIGH 7.8EPSS 19.9%

Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.

CVSS v3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
19.93% chance of exploitation in the next 30 days, 97th percentile
Published
2017-09-23
Updated
2024-08-05

Metasploit modules (1)

ExploitDB entries (2)

References

Related