vendor:
Dup Scout Enterprise
by:
Andrés Roldán
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: Dup Scout Enterprise
Affected Version From: 10.0.18
Affected Version To: 10.0.18
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro x64
2020
Dup Scout Enterprise 10.0.18 – ‘sid’ Remote Buffer Overflow (SEH)
The 'sid' parameter in Dup Scout Enterprise 10.0.18 is vulnerable to a remote buffer overflow. By sending a specially crafted request to the server, an attacker can overflow the buffer and potentially execute arbitrary code on the target system.
Mitigation:
Update to the latest version of Dup Scout Enterprise to fix this vulnerability. Additionally, ensure that the software is not accessible from untrusted networks.