CVE-2020-36971

8.4

Nidesoft · 3GP Video Converter

Nidesoft 3GP Video Converter 2.6.18 is vulnerable to a local stack-based buffer overflow in the license registration parameter, allowing an attacker to execute arbitrary code.

Executive summary

A local stack-based buffer overflow in Nidesoft 3GP Video Converter 2.6.18 allows local attackers to execute arbitrary code via a crafted license key.

Vulnerability

The application fails to perform adequate bounds checking on the License Code field during the registration process. This stack-based buffer overflow (CWE-121) can be triggered by a local, unauthenticated user providing a specially crafted malicious string into the registration interface.

Business impact

Successful exploitation of this vulnerability allows for arbitrary code execution on the host system with the privileges of the user running the application. Given the CVSS score of 8.4, this represents a high-severity risk that could lead to full system compromise, data theft, or the installation of persistent malicious software. The impact is primarily restricted to the local environment but remains a critical concern for endpoint security.

Remediation

Immediate Action: Discontinue use of Nidesoft 3GP Video Converter 2.6.18, as there is no indication of a patched version available from the vendor.

Proactive Monitoring: Monitor endpoint processes for unusual child-process spawning or unexpected application crashes associated with the video converter.

Compensating Controls: Restrict the execution of the application via Group Policy or endpoint protection software to prevent unauthorized users from launching the binary.

Exploitation status

Public Exploit Available: Yes, a functional exploit is available via ExploitDB (EDB-ID 49034).

Analyst recommendation

Due to the lack of an available vendor patch and the presence of a publicly available exploit, the risk associated with this software is unacceptably high. Organizations should prioritize the removal of Nidesoft 3GP Video Converter from all workstations. If the software is required for business processes, it should be isolated from sensitive data and restricted to non-privileged user accounts until a secure alternative can be implemented.

Sources

Originally found and disclosed by Felipe Winsnes, per the CVE Program record.