vendor:
Mini Remote Control
by:
Securifera
9,8
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Mini Remote Control
Affected Version From: 12.0.0.520
Affected Version To: 12.0.0.520
Patch Exists: YES
Related CWE: CVE-2016-2345
CPE: a:dameware:mini_remote_control:12.0.0.520
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Dameware Remote Controller RCE
A vulnerability in Dameware Remote Controller version 12.0.0.520 allows remote attackers to execute arbitrary code via a crafted packet sent to the listening service on port 6129. The vulnerability is due to improper bounds checking of the packet data, which can result in a buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of Dameware Remote Controller.