header-logo
Suggest Exploit
vendor:
LanHelper
by:
Rafael Pedrero
7.8
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: LanHelper
Affected Version From: 1.74
Affected Version To: 1.74
Patch Exists: YES
Related CWE: N/A
CPE: a:hainsoft:lanhelper
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows XP SP3
2019

LanHelper v1.74 – Denial of Service (PoC)

LanHelper v1.74 is vulnerable to a denial of service attack due to a local buffer overflow. An attacker can exploit this vulnerability by running LanHelper.exe, copying the content of LanHelper_Crash.txt or 6000 'A' characters to the clipboard, going to 'NT-Utilities' - 'Form Send Message' - 'Message' - 'Add' - 'Add target' and pasting the result from the python script, and then pasting the result from the python script in 'Message text:'. Clicking the 'Send' button will cause a crash.

Mitigation:

Upgrade to the latest version of LanHelper.
Source

Exploit-DB raw data: