vendor:
Advanced Host Monitor
by:
Peyman Forouzan
9.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Advanced Host Monitor
Affected Version From: 11.92 beta
Affected Version To: 11.92 beta
Patch Exists: YES
Related CWE: N/A
CPE: a:ks-soft:advanced_host_monitor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Winxp SP2 32-64 bit, Win7 Enterprise SP1 32-64 bit, Win10 Enterprise 32-64 bit
2019
Advanced Host Monitor 11.92 beta – Local Buffer Overflow (EggHunter)
Advanced Host Monitor 11.92 beta is vulnerable to a local buffer overflow vulnerability. An attacker can exploit this vulnerability by opening the application, navigating to Tools > Trace (or Telnet), pasting in contents from the egg.txt into the Host field, and starting the trace. The attacker can then close Advanced Host Monitor, navigate to Options > Startup, paste in contents from the egghunter-winxp-win7.txt or egghunter-win10.txt (depending on the Windows version) into the Load Specific HTML File field, save the changes, and wait a little for the shellcode (Calc) to open.
Mitigation:
Apply the latest security patches and updates to the affected software.