ZeroHour
Cisco Talospublished ()ingested

Vulnerability Spotlight: Memory corruption vulnerability in Daemon Tools Pro

highVulnerability exploited in the wildimportance 60CVE-2021-21832

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21832
A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767.

A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

NVD description · AI analysis pending
9.81% PoC
  • disc-soft daemon tools
Full article198 words · extracted from blog.talosintelligence.com · click to collapse

Friday, August 13, 2021 14:23

Piotr Bania of Cisco Talos discovered this vulnerability.

Cisco Talos recently discovered a memory corruption vulnerability in Disc Soft Ltd.'s Daemon Tools Pro.

Daemon Tools Pro is a professional emulation software that works with disc images and virtual drives. It allows the user to mount ISO images on Windows systems.

TALOS-2021-1295 (CVE-2021-21832) can cause memory corruption in the application if the user opens an adversary-created ISO file that causes an integer overflow. This vulnerability exists in the way the application parses ISOs.Cisco Talos worked with Disco Soft Ltd. to ensure that this issue is resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy.

Users are encouraged to update from Disc Soft Ltd. Daemon Tools Pro, version 8.3.0.0767 as soon as possible. Talos tested and confirmed this version of Daemon Tools could be exploited by this vulnerability.

The following SNORTⓇ rules will detect exploitation attempts against this vulnerability: 57546 and 57547. Additional rules may be released in the future and current rules are subject to change, pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vulnerability-spotlight-memory/