vendor:
Angry IP Scanner
by:
Fernando Cruz
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Angry IP Scanner
Affected Version From: 3.5.3
Affected Version To: 3.11
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro, 64-bit
2018
Angry IP Scanner 3.5.3 Denial of Service (PoC)
A denial of service vulnerability exists in Angry IP Scanner 3.5.3 due to a buffer overflow when copying a large amount of data to the clipboard. An attacker can exploit this vulnerability by running a python code to create a file with a large amount of data, copying the data to the clipboard, and then pasting it into the 'El valor no está disponible (sin resultados):' field in the 'Preferencias' tab of the 'Herramientas' toolbar. This will cause the application to crash.
Mitigation:
Upgrade to the latest version of Angry IP Scanner.