Description
Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution with potential remote code execution.
Problem types
Product status
Credits
boku
References
www.exploit-db.com/exploits/48087 (ExploitDB-48087)
en.softonic.com/author/pxcompany (Vendor Homepage)
www.vulncheck.com/advisories/cuckoo-clock-buffer-overflow (VulnCheck Advisory: Cuckoo Clock 5.0 - Buffer Overflow)