vendor:
NBMonitor
by:
Alejandra Sánchez
6.8
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: NBMonitor
Affected Version From: 1.6.5.0
Affected Version To: 1.6.5.0
Patch Exists: YES
Related CWE: N/A
CPE: a:nsauditor:nbmonitor:1.6.5.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
NBMonitor 1.6.5 – ‘Key’ Denial of Service (PoC)
NBMonitor 1.6.5 is vulnerable to a denial of service attack when a maliciously crafted input is sent to the 'Key' field. An attacker can exploit this vulnerability by running the python script 'NBMonitor.py', which will create a new file 'PoC.txt'. The attacker can then copy the text from the generated PoC.txt file to clipboard, open NBMonitor.exe, go to Register > Enter Registration Code, write anything in 'Name' field, paste clipboard in 'Key' field and click on button -> Ok, which will cause the application to crash.
Mitigation:
Upgrade to the latest version of NBMonitor 1.6.5 or later.