vendor:
Disk Sorter Enterprise
by:
Tulpa
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Disk Sorter Enterprise
Affected Version From: 9.0.24
Affected Version To: 9.0.24
Patch Exists: NO
Related CWE:
CPE: a:disk_sorter:enterprise:9.0.24
Platforms Tested: Windows 7 x86 Enterprise SP1
Disk Sorter Enterprise 9.0.24 Buffer Overflow Exploit
The exploit allows an attacker to execute arbitrary code and gain NT AUTHORITYSYSTEM privileges in Disk Sorter Enterprise version 9.0.24. The exploit does not require authentication and can be triggered by sending a specially crafted request. The exploit has been tested on Windows 7 x86 Enterprise SP1.
Mitigation:
The vendor has not released a patch for this vulnerability. Users are advised to avoid using the affected version or to implement additional security measures such as network segmentation and access controls.