vendor:
10-Strike Network Scanner
by:
Hashim Jawad - ihack4falafel
7.5
CVSS
HIGH
Local Buffer Overflow
Buffer Overflow
CWE
Product Name: 10-Strike Network Scanner
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE:
CPE: a:10_strike:network_scanner:3.0
Platforms Tested: Windows XP Professional - SP3 (x86)
2018
10-Strike Network Scanner 3.0 – Local Buffer Overflow (SEH)
The exploit takes advantage of a local buffer overflow vulnerability in 10-Strike Network Scanner 3.0. By copying a specially crafted payload into the 'Host name or address' field and performing a trace route action, an attacker can trigger the buffer overflow and gain control of the application. The exploit has been tested on Windows XP Professional - SP3 (x86) and may also affect other versions of the software.
Mitigation:
The vendor has not provided a patch for this vulnerability. Users are advised to avoid using the affected software or to implement additional security measures to protect against potential exploits.