Impact
Ease Audio Converter 5.30 has a denial of service flaw in its Audio Cutter feature. A local attacker can craft a malformed MP4 file that contains an oversized buffer, causing the MP4 parser to overflow and crash the application. This vulnerability is identified as a buffer-based race condition classified under CWE-226. The exploit does not lead to code execution or data disclosure; it simply renders the application unavailable to legitimate users.
Affected Systems
The issue affects only the Ease Audio Converter product released by Audiotool, specifically version 5.30. No other versions or related products are mentioned in the available information.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the exploit requires local access to the machine where the application runs, meaning it is limited to the context of the user who launches the program. Because the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, there is no evidence of widespread or active exploitation. The primary risk is a local denial of service that disrupts the availability of the application for its user, without affecting system confidentiality or integrity.
OpenCVE Enrichment