vendor:
Disk Savvy Enterprise
by:
Nipun Jaswal & Anurag Srivastava
7.5
CVSS
HIGH
Remote SEH Buffer Overflow
119
CWE
Product Name: Disk Savvy Enterprise
Affected Version From: 9.9.14
Affected Version To: 9.9.14
Patch Exists: NO
Related CWE:
CPE: a:disksavvy:enterprise:9.9.14
Platforms Tested: Windows 7 SP1 x64
2017
Disk Savvy Enterprise 9.9.14 Remote SEH Buffer Overflow
This exploit takes advantage of a buffer overflow vulnerability in Disk Savvy Enterprise version 9.9.14. By sending a specially crafted request to the server, an attacker can trigger a stack-based buffer overflow, overwriting the Structured Exception Handler (SEH) and gaining control of the program execution flow. This allows the attacker to execute arbitrary code on the target system.
Mitigation:
Apply the latest security patches provided by the vendor. Additionally, it is recommended to disable the web server feature in Disk Savvy Enterprise if it is not required.