vendor:
DiskBoss
by:
Arris Huijgen
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution
CWE
Product Name: DiskBoss
Affected Version From: Through 8.8.16
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2018-5262
CPE:
Platforms Tested: Windows 7 SP1 x64, Windows XP SP3 x86
2017
DiskBoss <= 8.8.16 - Unauthenticated Remote Code Execution
This exploit allows an attacker to execute remote code without authentication in DiskBoss versions up to 8.8.16. The vulnerability is present in the software editions free8416, pro8416, ult8416, srv8416, ent8416, ent8512, free8816, pro8816, ult8816, srv8816, and ent8816. The exploit has been tested on Windows 7 SP1 x64 and Windows XP SP3 x86. The CVE associated with this vulnerability is CVE-2018-5262.
Mitigation:
Upgrade to a version higher than 8.8.16.