Impact
Softdisk 3.0.3 contains a buffer overflow in the registration code dialog that allows a local attacker to crash the application by supplying an oversized string. The vulnerability is triggered by entering a 6000‑byte payload in the Registration Name field accessed through the Help menu’s Enter Registration Code dialog, resulting in a denial of service. The affected weakness is a buffer overflow, classified as CWE‑120.
Affected Systems
The vulnerability affects the Ezbsystems Softdisk product, specifically version 3.0.3. No other product versions are listed as affected, so older or patched versions may not contain the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is local, requiring an attacker to run Softdisk and supply the oversized input; it does not provide remote code execution or other privilege escalation. The product is not listed in the CISA KEV catalog, reducing immediate enterprise concern but still necessitating user awareness.
OpenCVE Enrichment