Impact
UltraISO 9.7.1.3519 contains a local buffer overflow in the Output FileName field of the Make CD/DVD Image dialog; attackers can craft a 304‑byte string to overwrite Structured Exception Handler (SEH) records and cause a crash. The vulnerability allows an adversary to trigger a denial of service by simply pasting the malicious string into the dialog, without executing arbitrary code, but the denial of service can be leveraged to disrupt system availability.
Affected Systems
The affected product is UltraISO version 9.7.1.3519 for Windows; earlier version 9.35 is also listed but the specific vulnerability is reported for 9.7.1.3519. Users running this version on any Windows operating system are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity; the EPSS score is not available, so the exploitation probability cannot be quantified, and the issue is not listed in CISA’s KEV catalog, implying no known active exploitation. The vulnerability is local, requiring an attacker to interact with the user interface or supply a crafted filename on the machine, so it is unlikely to be exploited remotely without user cooperation. Nevertheless, because it causes a crash that can affect critical processes, it should be treated as a significant risk to system availability.
OpenCVE Enrichment