CVE-2024-10093

A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.280758 Permissions Required
https://vuldb.com/?id.280758 Third Party Advisory
https://vuldb.com/?submit.420798 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vso-software:convertxtodvd:7.0.0.83:*:*:*:*:*:*:*

History

01 Nov 2024, 18:07

Type Values Removed Values Added
References () https://vuldb.com/?ctiid.280758 - () https://vuldb.com/?ctiid.280758 - Permissions Required
References () https://vuldb.com/?id.280758 - () https://vuldb.com/?id.280758 - Third Party Advisory
References () https://vuldb.com/?submit.420798 - () https://vuldb.com/?submit.420798 - Third Party Advisory
First Time Vso-software convertxtodvd
Vso-software
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como crítica en VSO ConvertXtoDvd 7.0.0.83. Se trata de una función desconocida de la librería avcodec.dll del archivo ConvertXtoDvd.exe. La manipulación genera una ruta de búsqueda no controlada. Es necesario atacar de forma local. El exploit se ha hecho público y puede utilizarse. Se contactó al proveedor con antelación sobre esta revelación, pero no respondió de ninguna manera.
CPE cpe:2.3:a:vso-software:convertxtodvd:7.0.0.83:*:*:*:*:*:*:*

17 Oct 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-17 23:15

Updated : 2024-11-01 18:07


NVD link : CVE-2024-10093

Mitre link : CVE-2024-10093

CVE.ORG link : CVE-2024-10093


JSON object : View

Products Affected

vso-software

  • convertxtodvd
CWE
CWE-427

Uncontrolled Search Path Element