CVE-2020-37198
7.5DigitalVolcano Software · Duplicate Cleaner Pro
DigitalVolcano Duplicate Cleaner Pro 4.1.3 is susceptible to a stack-based buffer overflow, allowing an attacker to cause an application crash via a crafted 6000-byte payload in the license key field.
Executive summary
A stack-based buffer overflow in DigitalVolcano Duplicate Cleaner Pro 4.1.3 allows an unauthenticated attacker to trigger a denial of service condition.
Vulnerability
The application suffers from a stack-based buffer overflow (CWE-121) in its license activation function. An unauthenticated attacker can inject a 6000-byte payload into the license key field, which results in an immediate application crash.
Business impact
Successful exploitation of this vulnerability results in a denial of service for the affected software. While the CVSS score of 7.5 indicates a high severity, the primary impact is the loss of application availability. This could disrupt administrative workflows that rely on Duplicate Cleaner Pro for data management and cleanup tasks.
Remediation
Immediate Action: Users should ensure they are running the latest version of Duplicate Cleaner Pro, as older versions like 4.1.3 are confirmed to be vulnerable. If an update is not immediately available, restrict access to the application interface to authorized personnel only.
Proactive Monitoring: Security teams should monitor system logs for unusual application crash events or recurring process failures associated with the Duplicate Cleaner Pro executable.
Compensating Controls: Since the attack vector requires local interaction or user-provided input in the license field, ensure that endpoint protection software is configured to detect and block malicious buffer overflow attempts in user-space applications.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via the Exploit Database (EDB-ID: 47873).
Analyst recommendation
The vulnerability presents a clear risk of service disruption for users of the affected software. Organizations currently running version 4.1.3 or earlier should prioritize updating to the latest secure version provided by DigitalVolcano Software. If immediate patching is not feasible, restrict application access to prevent unauthorized users from triggering the crash condition.
Sources
Originally found and disclosed by Achilles, per the CVE Program record.
- ExploitDB-47873 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: Duplicate Cleaner Pro 4 - Denial of Service Third-party advisory