vendor:
SpotAuditor
by:
ZwX
5.5
CVSS
MEDIUM
Denial of Service
DoS
CWE
Product Name: SpotAuditor
Affected Version From: 5.3.2002
Affected Version To: 5.3.2002
Patch Exists: NO
Related CWE:
CPE: a:nsauditor:spotauditor:5.3.2
Platforms Tested: Windows 7
2019
SpotAuditor 5.3.2 – ‘Name’ Denial Of Service
This exploit allows an attacker to create a file with a large buffer and crash the SpotAuditor software by pasting the characters from the file into the 'Name' field.
Mitigation:
Update to a patched version of the software.