7.8
CVSSv3

CVE-2017-14627

Published: 23/09/2017 Updated: 14/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote malicious users to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cyberlink labelprint 2.5

Exploits

#!/usr/bin/python # Exploit Title: CyberLink LabelPrint <=25 File Project Processing Unicode Stack Overflow # Date: September 23, 2017 # Exploit Author: f3ci # Vendor Homepage: wwwcyberlinkcom/ # Software Link: updatecyberlinkcom/Retail/Power2Go/DL/TR170323-021/CyberLink_Power2Go_Downloaderexe # Version: 25 # Tested on: Win ...
CyberLink LabelPrint versions prior to 25 SEH unicode buffer overflow exploit ...