vendor:
Arm Whois
by:
zephyr
9.3
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Arm Whois
Affected Version From: 3.11
Affected Version To: 3.11
Patch Exists: YES
Related CWE: N/A
CPE: a:armcode:arm_whois:3.11
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Arm Whois 3.11 – Buffer Overflow (ASLR)
Arm Whois 3.11 is vulnerable to a buffer overflow vulnerability due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted payload to the vulnerable application, which can lead to arbitrary code execution. This vulnerability affects Windows Vista Ultimate SP1 x86 unpatched.
Mitigation:
The vendor has released a patch to address this vulnerability.