Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. At...
Description
Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind shell.
AI Analyst Comment
Remediation
Update Kingdia CD Extractor Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Kingdia
PRODUCT: CD Extractor
AFFECTED_VERSIONS: 3.0.2
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
Kingdia CD Extractor 3.0.2 contains a buffer overflow in the registration name field, enabling remote code execution via a payload exceeding 256 bytes.
Executive Summary:
A critical buffer overflow in Kingdia CD Extractor 3.0.2 enables remote code execution through a malicious registration payload, posing a severe risk of system compromise.
Vulnerability Details
CVE-ID: CVE-2021-47774
Affected Software: Kingdia CD Extractor
Affected Versions: 3.0.2
Vulnerability: The vulnerability resides in the registration name input field, which lacks adequate bounds checking. An unauthenticated attacker can overwrite the Structured Exception Handler with a malicious payload to gain remote code execution via a bind shell.
Business Impact
A CVSS score of 9.8 reflects the high risk of total system compromise, including unauthorized data access and full remote control by an attacker. This represents a critical threat to the confidentiality, integrity, and availability of any host running the affected software.
Remediation Plan
Immediate Action: Update Kingdia CD Extractor to the latest version immediately to resolve the vulnerable input handling.
Proactive Monitoring: Review system and application logs for unusual inbound network traffic or attempts to initiate unauthorized shells.
Compensating Controls: Ensure the application is run with the least privilege necessary and utilize Endpoint Detection and Response (EDR) tools to detect suspicious child process spawning.
Exploitation Status
Public Exploit Available: Not specified
Analyst Notes: As of Jan 15, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
This vulnerability allows for full remote code execution and must be treated with the highest urgency. Organizations should apply the vendor-provided security update immediately and restrict access to the application's configuration interfaces.