vendor:
LANState
by:
Hodorsec
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: LANState
Affected Version From: v9.32 x86
Affected Version To: v9.32 x86
Patch Exists: NO
Related CWE: N/A
CPE: 10-strike.com/lanstate/lanstate-setup.exe
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 x86 SP1 - Build 7601
2020
10Strike LANState 9.32 – ‘Force Check’ Buffer Overflow (SEH)
Exploits the 'Force Check' option when listing the Host Checks in option 'Check List'. Entering an overly long string, results in a crash which overwrites SEH.
Mitigation:
Ensure that user input is validated and sanitized before being used in the application.