CVE-2021-47797
7.5Leawo · Prof. Media
Leawo Prof. Media 11.0.0.1 is vulnerable to a buffer overflow in the registration interface, allowing an unauthenticated attacker to cause a denial of service via a crafted payload.
Executive summary
A buffer overflow vulnerability in Leawo Prof. Media 11.0.0.1 allows an attacker to crash the application, resulting in a denial of service condition.
Vulnerability
The application contains a buffer overflow vulnerability (CWE-120) in the activation keycode field. An unauthenticated attacker can trigger an application crash by submitting a 6000-byte string into the registration interface.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the software unusable for the end user. While the CVSS score of 7.5 indicates a high severity, the impact is localized to the application level rather than systemic infrastructure compromise. This flaw may disrupt business processes that rely on the software for media conversion tasks.
Remediation
Immediate Action: Users should check the vendor website for available updates and apply them immediately if a patched version is provided. If no patch is available, avoid entering untrusted or excessively long strings into the activation interface.
Proactive Monitoring: Security teams should monitor system logs for abnormal application crashes or repeated process failures associated with the Leawo Prof. Media executable.
Compensating Controls: Ensure that endpoint protection software is active to monitor for suspicious process behavior, and restrict access to the application to authorized users to minimize the attack surface.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via ExploitDB (EDB-ID: 50153).
Analyst recommendation
Given the availability of a public proof-of-concept and the ease of exploitation, users of Leawo Prof. Media 11.0.0.1 should prioritize testing and applying any available vendor patches. If the software is no longer supported or no fix is forthcoming, consider removing the application from production environments to eliminate the risk of service disruption.
Sources
Originally found and disclosed by Achilles, per the CVE Program record.
- ExploitDB-50153 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: Leawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC) Third-party advisory