Description
PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the vulnerability through the Create SC feature by selecting a crafted BMP file with an oversized buffer, causing the application to crash.
Problem types
Sensitive Information in Resource Not Removed Before Reuse
Product status
Credits
Alejandra Sánchez
References
www.exploit-db.com/exploits/46708 (ExploitDB-46708)
www.uvnc.com/home.html (Official Product Homepage)
www.uvnc.eu/download/pchw2/PCHelpWareV2.msi (Product Reference)
www.vulncheck.com/...arev2-denial-of-service-via-sc-creation (VulnCheck Advisory: PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation)