vendor:
Bandwidth Monitor
by:
absolomb
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Bandwidth Monitor
Affected Version From: 3.7
Affected Version To: 3.7
Patch Exists: NO
Related CWE: Unknown
CPE: a:10_strike:bandwidth_monitor:3.7
Platforms Tested: Windows
2018
10-Strike Bandwidth Monitor 3.7 – Local Buffer Overflow SEH
The 10-Strike Bandwidth Monitor 3.7 software is vulnerable to a local buffer overflow exploit. By running a script and copying the generated code to the clipboard, an attacker can execute arbitrary code and gain unauthorized access to the system. This can be done either by pasting the code into the Bandwidth Monitor application or by going to the Help tab and clicking Registration. This exploit allows for the execution of a shell.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. Users are advised to update to a newer version of the software or consider alternative solutions.