vendor:
Faleemi Desktop Software for Windows
by:
Anonymous
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Faleemi Desktop Software for Windows
Affected Version From: Faleemi Desktop Software for Windows v1.8
Affected Version To: Faleemi Plus Desktop Software for Windows(Beta) v1.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:faleemi:faleemi_desktop_software_for_windows
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Faleemi Desktop Software for Windows- (DDNS/IP) Local Buffer Overflow
Faleemi Desktop Software for Windows and its Beta version (Faleemi Plus Desktop Software for Windows(Beta)) are vulnerable to Buffer Overflow exploit. When overly input is given to DDNS/IP parameter, it overflows the buffer corrupting EIP which can utilized cleverly for local arbitrary code execution. If this software is running as admin and if a low priv user has access to this application to enter new device, he can exploit the Buffer Overflow in the DDNS/IP parameter to obtain Admin privs. An attacker could exploit this vulnerability to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Restrict access to the application and ensure that only authorized users have access to the application.