vendor:
Network Inventory Explorer
by:
Felipe Winsnes
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Network Inventory Explorer
Affected Version From: 8.54
Affected Version To: 8.54
Patch Exists: YES
Related CWE: N/A
CPE: a:10-strike:network_inventory_explorer:8.54
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2020
10-Strike Network Inventory Explorer 8.54 – ‘Add’ Local Buffer Overflow (SEH)
10-Strike Network Inventory Explorer 8.54 is vulnerable to a local buffer overflow vulnerability when a maliciously crafted input is supplied to the 'Computer' parameter under the title 'Computer Card' in the 'Add' menu. This can be exploited to execute arbitrary code by overwriting the Structured Exception Handler (SEH) with a malicious payload.
Mitigation:
Upgrade to the latest version of 10-Strike Network Inventory Explorer.