PT-2025-34300 · Unknown · Millenium Mp3 Studio

Published

2025-08-21

·

Updated

2025-08-22

·

CVE-2009-20002

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Millenium MP3 Studio versions through 2.0
Description: Millenium MP3 Studio versions up to and including 2.0 are vulnerable to a stack-based buffer overflow when parsing .pls playlist files. The application does not properly validate the length of the File1 field within the playlist, allowing an attacker to craft a malicious .pls file that overwrites the Structured Exception Handler (SEH) and executes arbitrary code. Exploitation requires the victim to open the file locally, though remote execution may be possible if the .pls extension is registered to the application and opened via a browser.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2009-20002

Affected Products

Millenium Mp3 Studio