vendor:
NVR SP2
by:
shinnai
7.5
CVSS
HIGH
Remote Buffer Overflow
Not provided
CWE
Product Name: NVR SP2
Affected Version From: NVR SP2 2.0
Affected Version To: NVR SP2 2.0
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
Not provided
[PoC2] NVR SP2 2.0 nvUnifiedControl.AUnifiedControl.1 (nvUnifiedControl.dll v. 1.1.45.0) “SetText()” Remote BoF (Heap Spray Technique)
This exploit targets the nvUnifiedControl.AUnifiedControl.1 control in NVR SP2 2.0, specifically the SetText() function. By exploiting a heap spray technique, an attacker can trigger a remote buffer overflow vulnerability in the nvUnifiedControl.dll version 1.1.45.0. This vulnerability allows the attacker to execute arbitrary code on the target system.
Mitigation:
No mitigation or remediation provided