PT-2022-26201 · Poweriso · Poweriso

Piotr Bania

·

Published

2022-12-08

·

Updated

2022-12-22

·

CVE-2022-41992

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PowerISO version 8.3
Description A memory corruption issue exists in the VHD File Format parsing CXSPARSE record functionality. This can be triggered by a specially-crafted file, leading to an out-of-bounds write. A victim needs to open a malicious file to activate this issue. The problem arises because the 'number of blocks' value from the CXSPARSE record is not properly checked, allowing an attacker to control the loop counter and leading to arbitrary memory writing.
Recommendations For PowerISO version 8.3, ensure you are using the version with the latest bug fixes, as the developer has fixed the issue in a subsequent update, although no specific version number for the fix was assigned.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-41992

Affected Products

Poweriso