vendor:
eDirectory DHost Console
by:
d0lc3
7,8
CVSS
HIGH
Local Denial of Service
119
CWE
Product Name: eDirectory DHost Console
Affected Version From: 8.8 SP3 (20216.67)
Affected Version To: 8.8 SP3 (20216.67)
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: win32 xp sp3 (spa)
2010
Novel eDirectory DHost Console 8.8 SP3 Local SEH Overwrite
DHostCon.exe is prone to local denial of service caused by stack overflow triggered if user-supplied parameters are too long (1074 bytes). Due nature of this vulnerabilty, attackers could exploit this issue to execute arbitrary code on local host.
Mitigation:
Ensure that user-supplied parameters are of appropriate length.