vendor:
Frigate Professional
by:
Paras Bhatia
N/A
CVSS
HIGH
Local Buffer Overflow
Buffer Overflow
CWE
Product Name: Frigate Professional
Affected Version From: 3.36.0.9
Affected Version To: 3.36.0.9
Patch Exists: NO
Related CWE:
CPE: a:frigate_professional:frigate_professional:3.36.0.9
Platforms Tested: Windows 7 Ultimate Service Pack 1 (32 bit - English)
2020
Frigate Professional 3.36.0.9 – ‘Find Computer’ Local Buffer Overflow (SEH) (PoC)
The Frigate Professional software version 3.36.0.9 is vulnerable to a local buffer overflow when the 'Find Computer' feature is used. By pasting a specially crafted payload into the 'Computer Name' field, an attacker can trigger a buffer overflow and execute arbitrary code. This proof-of-concept exploit demonstrates how to exploit the vulnerability to run the Windows calculator (calc.exe).
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of Frigate Professional or apply any patches or security updates provided by the vendor.