Impact
The vulnerability is a stack-based buffer overflow in Easyboot 6.6.0 exposed through the Replace Text function. When a local user supplies an oversized string—such as a 7000‑byte payload—into the text fields, the application crashes, resulting in a denial of service. This flaw falls under CWE-120, indicating insufficient bounds checking during string handling.
Affected Systems
The affected product is Easyboot 6.6.0 from Ezbsystems. Only this specific version is documented as vulnerable, and the flaw is triggered through the normal user interface rather than through any remote interface.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity with local impact. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need local access to the machine running Easyboot and must manually trigger the Replace Text routine, which limits the attack surface to environments where the application is used by potentially untrusted users.
OpenCVE Enrichment