CVE-2020-37179

7.5

Nsasoft · APKF Product Key Finder

APKF Product Key Finder 2.5.8.0 is vulnerable to a buffer overflow in the registration name field, allowing an attacker to crash the application via a crafted 1000-character input.

Executive summary

A buffer overflow vulnerability in Nsasoft APKF Product Key Finder 2.5.8.0 allows an attacker to trigger a denial of service through a specially crafted registration input.

Vulnerability

The application fails to perform adequate size validation on the Name input field during the registration process, leading to a classic buffer overflow (CWE-120). This vulnerability can be triggered by an attacker without requiring authentication, though it requires user interaction to perform the registration steps.

Business impact

Successful exploitation results in an application crash, causing a denial of service for the product key recovery functionality. While this impact is limited to the local instance, it disrupts administrative workflows and productivity for users relying on the software to manage product license keys.

Remediation

Immediate Action: Discontinue use of version 2.5.8.0 and check the vendor website for an updated release that addresses this memory corruption flaw.

Proactive Monitoring: Monitor system logs for repeated application crashes or unexpected terminations of the APKF process, which may indicate exploitation attempts.

Compensating Controls: Restrict access to the application to authorized personnel only, and implement endpoint security controls that monitor for unauthorized memory access or process injection attempts.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exploit is available via the Exploit Database (EDB-ID: 47937).

Analyst recommendation

The presence of a publicly available proof-of-concept necessitates immediate attention to this vulnerability. Organizations using Nsasoft APKF Product Key Finder should prioritize updating to the latest version to prevent potential service disruption and ensure the integrity of the application environment.

Sources

Originally found and disclosed by Ismail Tasdelen, per the CVE Program record.