vendor:
WinaXe Plus
by:
Peter Baris
N/A
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: WinaXe Plus
Affected Version From: 8.7
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows Server 2008 R2 x64, Windows 7 SP1 x64, Windows 10 Pro x64, Windows Server 2012 R2 x64, Windows Server 2016 x64
2017
WinaXe Plus 8.7 – lpr remote buffer overflow
This exploit takes advantage of a buffer overflow vulnerability in WinaXe Plus 8.7. By sending a specially crafted network printer request, an attacker can execute arbitrary code on the target system. The exploit has been tested on various versions of Windows, including Windows Server 2008 R2 x64, Windows 7 SP1 x64, Windows 10 Pro x64, Windows Server 2012 R2 x64, and Windows Server 2016 x64.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update to the latest version of WinaXe Plus.