CVE-2019-25560
7.5Lyric Video Creator · Lyric Video Creator
Lyric Video Creator 2.1 is susceptible to a denial of service vulnerability triggered by processing malformed MP3 files, which allows an attacker to crash the application.
Executive summary
A denial of service vulnerability in Lyric Video Creator 2.1 allows unauthenticated attackers to crash the application by providing a specially crafted MP3 file.
Vulnerability
This vulnerability is a denial of service flaw stemming from improper handling of resource buffers. An unauthenticated attacker can trigger the crash by utilizing the Browse song functionality to process a malformed MP3 file containing an oversized buffer.
Business impact
The exploitation of this vulnerability results in the immediate termination of the Lyric Video Creator application, leading to a loss of availability for the software. While the CVSS score of 7.5 reflects a high severity for availability impact, the primary business risk is localized disruption of service for users who rely on the tool for media production.
Remediation
Immediate Action: As no official patch is currently available, users should restrict access to the application and avoid opening MP3 files from untrusted sources.
Proactive Monitoring: Security teams should monitor system logs for frequent application crashes or unexpected service termination events associated with the Lyric Video Creator process.
Compensating Controls: Deploy endpoint protection solutions that can scan files for anomalies or block the execution of unrecognized media files if they originate from untrusted network locations.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists in the Exploit Database (EDB-ID: 46816).
Analyst recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-supplied patch, organizations should consider this software a high-risk component. Administrators must ensure users are aware of the risk and restrict the application to processing only trusted media files until the vendor releases a secure version.
Sources
Originally found and disclosed by Alejandra Sánchez, per the CVE Program record.
- ExploitDB-46816 Exploit / PoC
- Official Product Homepage
- Product Reference
- VulnCheck Advisory: Lyric Video Creator 2.1 Denial of Service via MP3 File Third-party advisory