PT-2024-14937 · X Ways · Winhex
Rafael Pedrero
·
Published
2024-10-07
·
Updated
2024-10-11
·
CVE-2023-6361
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Winhex versions 16.1 SR-1 and 20.4
Description
A buffer overflow vulnerability has been discovered in Winhex, affecting the Structured Exception Handler (SEH) registers. This issue could allow attackers to execute arbitrary code via a long filename argument.
Recommendations
For versions 16.1 SR-1 and 20.4, update to the latest version to mitigate risks.
As a temporary workaround, consider restricting the use of long filename arguments until a patch is available.
Avoid using the
filename argument in affected areas until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winhex