← Advisories

NCH Software Express Burn Plus 4.68 EBP Project File Handling Buffer Overflow PoC

High
Advisory ID
ZSL-2014-5166
Release Date
21 January 2014
Vendor
Affected Version
4.68
CVE
N/A
Tested On
Microsoft Windows 7 Professional SP1 EN
Summary

Express Burn is a program that allows you to create and copy many kinds of disc media, including Audio (audio CDs / .mp3 CDs), Video (DVDs), and Data (CDs / DVDs / Blu-ray).

Description

The vulnerability is caused due to a boundary error in the processing of a project file, which can be exploited to cause a unicode buffer overflow when a user opens e.g. a specially crafted .EBP file. Successful exploitation could allow execution of arbitrary code on the affected machine.

(1144.1488): Access violation - code c0000005 (first chance) First chance exceptions are reported before any exception handling. This exception may be expected and handled. *** ERROR: Module load completed but symbols could not be loaded for C:\Program Files (x86)\NCH Software\ExpressBurn\expressburn.exe eax=03418568 ebx=004034ec ecx=00000041 edx=00011a98 esi=03429428 edi=001893df eip=004679ef esp=00185f18 ebp=00187254 iopl=0 nv up ei pl nz na pe nc cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010206 expressburn+0x679ef: 004679ef 66890c02 mov word ptr [edx+eax],cx ds:002b:0342a000=???? 0:000> d eax 03418568 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 03418578 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 03418588 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 03418598 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 034185a8 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 034185b8 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 034185c8 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A. 034185d8 41 00 41 00 41 00 41 00-41 00 41 00 41 00 41 00 A.A.A.A.A.A.A.A.
Proof of Concept
Disclosure Timeline
22.01.2014Vendor has some knowledge about the issue.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
21.01.2014Initial release
22.02.2014Added vendor status and reference [2] and [3]
24.01.2014Added reference [4], [5], [6], [7] and [8]