vendor:
Remote Process Explorer
by:
Rafael Pedrero
7.8
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: Remote Process Explorer
Affected Version From: 1.0.0.16
Affected Version To: 1.0.0.16
Patch Exists: YES
Related CWE: N/A
CPE: a:lizardsystems:remote_process_explorer:1.0.0.16
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3
2019
Remote Process Explorer v1.0.0.16 – Denial of Service (PoC) and SEH overwritten Crash PoC
Remote Process Explorer v1.0.0.16 is vulnerable to a denial of service (DoS) attack due to a local buffer overflow. The vulnerability can be triggered by copying a specially crafted string to the clipboard and then pasting it into the 'Add computer' textbox. This will cause the application to crash and overwrite the SEH chain of thread 00000144.
Mitigation:
Upgrade to the latest version of Remote Process Explorer v1.0.0.16 or apply the patch provided by the vendor.