CVE-2020-37198

7.5

DigitalVolcano Software · Duplicate Cleaner Pro

DigitalVolcano Duplicate Cleaner Pro 4.1.3 is susceptible to a stack-based buffer overflow, allowing an attacker to cause an application crash via a crafted 6000-byte payload in the license key field.

Executive summary

A stack-based buffer overflow in DigitalVolcano Duplicate Cleaner Pro 4.1.3 allows an unauthenticated attacker to trigger a denial of service condition.

Vulnerability

The application suffers from a stack-based buffer overflow (CWE-121) in its license activation function. An unauthenticated attacker can inject a 6000-byte payload into the license key field, which results in an immediate application crash.

Business impact

Successful exploitation of this vulnerability results in a denial of service for the affected software. While the CVSS score of 7.5 indicates a high severity, the primary impact is the loss of application availability. This could disrupt administrative workflows that rely on Duplicate Cleaner Pro for data management and cleanup tasks.

Remediation

Immediate Action: Users should ensure they are running the latest version of Duplicate Cleaner Pro, as older versions like 4.1.3 are confirmed to be vulnerable. If an update is not immediately available, restrict access to the application interface to authorized personnel only.

Proactive Monitoring: Security teams should monitor system logs for unusual application crash events or recurring process failures associated with the Duplicate Cleaner Pro executable.

Compensating Controls: Since the attack vector requires local interaction or user-provided input in the license field, ensure that endpoint protection software is configured to detect and block malicious buffer overflow attempts in user-space applications.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exploit is available via the Exploit Database (EDB-ID: 47873).

Analyst recommendation

The vulnerability presents a clear risk of service disruption for users of the affected software. Organizations currently running version 4.1.3 or earlier should prioritize updating to the latest secure version provided by DigitalVolcano Software. If immediate patching is not feasible, restrict application access to prevent unauthorized users from triggering the crash condition.

Sources

Originally found and disclosed by Achilles, per the CVE Program record.