CVE-2017-8367

moderate-risk
Published 2017-04-30

Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD Burner, MP3 WAV to CD Burner, My Video Converter, Easy AVI DivX Converter, Easy Video to iPod Converter, Easy Video to PSP Converter, Easy Video to 3GP Converter, Easy Video to MP4 Converter, and Easy Video to iPod/MP4/PSP/3GP Converter allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long username.

Do I need to act?

-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10 High
LOCAL / LOW complexity

Affected Products (19)

Easy Avi Divx Converter
Easy Dvd Creator
Easy Mov Converter
Easy Mpeg\/Avi\/Divx\/Wmv\/Rm To Dvd
Easy Mpeg To Dvd Burner
Easy Rm Rmvb To Dvd Burner
Easy Video To 3Gp Converter
Easy Video To Ipod Converter
Easy Video To Mp4 Converter
Easy Wmv\/Asf\/Asx To Dvd Burner
Mp3\/Avi\/Mpeg\/Wmv\/Rm To Audio Cd Burner
Mp3\/Wav\/Ogg\/Wma\/Ac3 To Cd Burner
Easy Avi\/Divx\/Xvid To Dvd Burner
Easy Cd Dvd Copy
Easy Mov Converter
Easy Video To Ipod\/Mp4\/Psp\/3Gp Converter
Easy Video To Psp Converter
Mp3 Wav To Cd Burner
My Video Converter

Affected Vendors

43
/ 100
moderate-risk
Severity 24/34 · High
Exploitability 0/34 · Minimal
Exposure 19/34 · Moderate