Home
HIGH: 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
16.1 SR-1
affected
20.4
affected
Description
A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.
Problem types
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
16.1 SR-1
20.4
Credits
Rafael Pedrero
References
www.incibe.es/...tices/aviso/multiple-vulnerabilities-winhex