vendor:
Disk Savvy Enterprise
by:
Daniel Teixeira
9.8
CVSS
CRITICAL
Remote Buffer Overflow
119
CWE
Product Name: Disk Savvy Enterprise
Affected Version From: 10.4.18
Affected Version To: 10.4.18
Patch Exists: NO
Related CWE: CVE-2018-6481
CPE: a:disksavvy:enterprise:10.4.18
Platforms Tested: Windows 7 x86
2018
Disk Savvy Enterprise v10.4.18 Server – Unauthenticated Remote Buffer Overflow SEH
The exploit allows an unauthenticated remote attacker to execute arbitrary code on the target system by exploiting a buffer overflow vulnerability in Disk Savvy Enterprise v10.4.18 Server. By sending a specially crafted request, an attacker can overwrite the Structured Exception Handler (SEH) and gain control of the program flow.
Mitigation:
Apply the latest patch or upgrade to a non-vulnerable version of Disk Savvy Enterprise.