Description
Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gokkul
References
www.exploit-db.com/exploits/47867 (ExploitDB-47867)
www.nsauditor.com/ (Vendor Homepage)
www.vulncheck.com/...ce-product-key-finder-denial-of-service (VulnCheck Advisory: Office Product Key Finder 1.5.4 - Denial of Service)