vendor:
InduSoft Web Studio
by:
Luis Martinez
7.8
CVSS
HIGH
Local Buffer Overflow (SEH Unicode)
119
CWE
Product Name: InduSoft Web Studio
Affected Version From: 8.1 SP1
Affected Version To: 8.1 SP1
Patch Exists: YES
Related CWE: N/A
CPE: a:indusoft:indusoft_web_studio:8.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 en
2018
InduSoft Web Studio 8.1 SP1 – ‘Tag Name’ Buffer Overflow (SEH)
InduSoft Web Studio 8.1 SP1 is vulnerable to a local buffer overflow (SEH Unicode) when a specially crafted 'Tag Name' is pasted into the application. This can be exploited by an attacker to execute arbitrary code on the target system.
Mitigation:
Upgrade to the latest version of InduSoft Web Studio 8.1 SP1.