PT-2021-10364 · Finalwire · Aida64 Engineer

Published

2021-02-18

·

Updated

2021-07-21

·

CVE-2020-19513

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FinalWire Ltd AIDA64 Engineer version 6.00.5100
Description: The issue allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler. This is due to a buffer overflow.
Recommendations: For version 6.00.5100, consider applying a patch or fix to prevent the buffer overflow and subsequent code execution. As a temporary workaround, restrict the ability to create crafted inputs that could trigger the buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-19513

Affected Products

Aida64 Engineer