vendor:
HWiNFO
by:
bzyo
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: HWiNFO
Affected Version From: 5.82-3410
Affected Version To: 5.82-3410
Patch Exists: Yes
Related CWE: N/A
CPE: a:hwinfo:hwinfo
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x86
2018
HWiNFO 5.82-3410 – Denial of Service
HWiNFO 5.82-3410 is vulnerable to a denial of service attack. An attacker can craft a malicious file containing a large amount of data and send it to the application. When the application attempts to process the file, it will crash and overwrite the EIP register. This can be exploited to execute arbitrary code.
Mitigation:
The vendor has released a patch to address this vulnerability.