vendor:
iSmartViewPro
by:
Rodrigo Eduardo Rodriguez
7.8
CVSS
HIGH
Buffer Overflow Local
119
CWE
Product Name: iSmartViewPro
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: YES
Related CWE: N/A
CPE: a:securimport:ismartviewpro:1.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2018
iSmartViewPro 1.5 – ‘Device Alias’ Buffer Overflow
iSmartViewPro 1.5 is vulnerable to a buffer overflow in the 'Device Alias' field. An attacker can exploit this vulnerability by running a python code to generate a malicious file, copying the content of the file to the clipboard, and then pasting it into the 'Device Alias' field. This will cause a buffer overflow and allow the attacker to execute arbitrary code.
Mitigation:
Upgrade to the latest version of iSmartViewPro 1.5