vendor:
Dup Scout Enterprise
by:
Chris Higgins, sickness
7.5
CVSS
HIGH
Stack Buffer Overflow
121
CWE
Product Name: Dup Scout Enterprise
Affected Version From: 10.0.18
Affected Version To: 10.0.18
Patch Exists: NO
Related CWE:
CPE: a:dup_scout_enterprise:dup_scout_enterprise:10.0.18
Platforms Tested: Windows
2017
Dup Scout Enterprise Login Buffer Overflow
This module exploits a stack buffer overflow in Dup Scout Enterprise 10.0.18. The buffer overflow exists via the web interface during login. This gives NT AUTHORITYSYSTEM access.
Mitigation:
Apply the vendor patch or update to a non-vulnerable version of Dup Scout Enterprise.