vendor:
DiskBoss
by:
MasterVlad
7.8
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: DiskBoss
Affected Version From: 7.7.14
Affected Version To: 7.7.14
Patch Exists: YES
Related CWE: N/A
CPE: a:flexense:diskboss
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32-bit
2020
DiskBoss 7.7.14 – ‘Reports and Data Directory’ Buffer Overflow (SEH Egghunter)
A buffer overflow vulnerability exists in DiskBoss 7.7.14 due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by supplying a specially crafted input to the 'Reports and Data Directory' field in the DiskBoss Options menu. This can result in arbitrary code execution in the context of the application.
Mitigation:
Upgrade to the latest version of DiskBoss.