vendor:
Disk Savvy Enterprise
by:
Anurag Srivastava
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Disk Savvy Enterprise
Affected Version From: 9.9.14
Affected Version To: 9.9.14
Patch Exists: YES
Related CWE: N/A
CPE: a:disksavvy:disk_savvy_enterprise:9.9.14
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Ultimate x64bit and Windows 10 Home Edition x64
2017
Disk Savvy Enterprise v9.9.14 – ‘Import Command’ Buffer Overflow
Disk Savvy Enterprise v9.9.14 is vulnerable to a buffer overflow vulnerability when importing a specially crafted XML file. An attacker can exploit this vulnerability by creating a malicious XML file and then importing it into the application. This will cause a buffer overflow and allow the attacker to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of Disk Savvy Enterprise v9.9.14 or later.