vendor:
DeviceLock Plug and Play Auditor
by:
Youssef mami
7.8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: DeviceLock Plug and Play Auditor
Affected Version From: 5.72
Affected Version To: 5.72
Patch Exists: YES
Related CWE: CVE-2018-10655
CPE: a:devicelock:devicelock_plug_and_play_auditor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
DeviceLock Plug and Play Auditor 5.72 – Unicode Buffer Overflow (SEH)
DeviceLock Plug and Play Auditor 'DLPnpAuditor.exe' is vulnerable to a Unicode type of buffer overflow, when supplied a specially crafted textfile using the 'scan network' from file option. The buffer overload payload will get converted to unicode character encoding. Unicode support is used by applications for internationalization purposes allowing a consistent way to visually represent different character sets on most systems around the world.
Mitigation:
Ensure that the application is updated to the latest version and that all security patches are applied.