CyberRota Analysis
AI-GeneratedVinchin Backup & Recovery versions up to 9.0.0.86562 are susceptible to a heap buffer overflow vulnerability that can be exploited by unauthenticated remote attackers through specially crafted TCP packets. This flaw may lead to process crashes or memory corruption, posing a risk to system stability and data integrity. Organizations using this software should prioritize patching to mitigate potential exploitation.
Original NVD Description
Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.