vendor:
Network Inventory Explorer
by:
Hashim Jawad - ihack4falafelx
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Network Inventory Explorer
Affected Version From: 8.54
Affected Version To: 8.54
Patch Exists: NO
Related CWE:
CPE: a:10-strike:network_inventory_explorer:8.54
Platforms Tested: Windows 7 Enterprise - SP1 (x86)
2018
10-Strike Network Inventory Explorer 8.54 – ‘Registration Key’ Buffer Overflow (SEH)
The 'Registration Key' field in 10-Strike Network Inventory Explorer 8.54 is vulnerable to a buffer overflow exploit. By pasting a specially crafted payload into the 'Registration Key' field, an attacker can overwrite the SEH (Structured Exception Handling) and execute arbitrary code.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of 10-Strike Network Inventory Explorer.