vendor:
RPCScan
by:
Nipun Jaswal
7,6
CVSS
HIGH
SEH Overwrite POC
119
CWE
Product Name: RPCScan
Affected Version From: 2.03
Affected Version To: 2.03
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Home Basic
2016
RPCScan v2.03 Hostname/IP Field SEH Overwrite POC
RPCScan v2.03 is vulnerable to a SEH Overwrite vulnerability. By supplying a malicious payload in the Hostname/IP field, an attacker can overwrite the SEH frame and execute arbitrary code. The offset to the SEH frame is 536 bytes and the address of the next SEH frame and the address of the handler code are both 4 bytes long.
Mitigation:
Upgrade to the latest version of RPCScan v2.03 or later.