Impact
A buffer overflow within the FreeDB Proxy Options dialog of MAGIX Music Editor 3.1 permits a local attacker to inject arbitrary code. The vulnerability arises when an attacker supplies an oversized string in the Server field and triggers the settings acceptance, causing a SEH overwrite. This flaw matches CWE‑787 and enables execution of malicious payloads on the affected system.
Affected Systems
MAGIX Music Editor 3.1, released by Magix. Only the 3.1 version is listed as affected, with no additional version range specified. The product is a desktop music editing application that contains the vulnerable dialog.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The exploit requires a local user with access to the machine and involves manipulating the CD menu to paste a crafted payload into the Server field. No network exposure is mentioned, and no publicly available exploits are cited, but the high CVSS implies a serious local compromise risk if exploited.
OpenCVE Enrichment