vendor:
LanSpy
by:
n30m1nd
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: LanSpy
Affected Version From: 2.0.0.155
Affected Version To: 2.0.0.155
Patch Exists: YES
Related CWE: N/A
CPE: a:lantricks:lanspy
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win7 32bit and Win10 64 bit
2016
LanSpy 2.0.0.155 – Buffer Overflow Exploit by n30m1nd
LanSpy 2.0.0.155 is vulnerable to a buffer overflow attack. This exploit was discovered by n30m1nd in 2016 and is tested on Win7 32bit and Win10 64 bit. The exploit code generates an 'addresses.txt' file which can be used to run the exploit. The exploit code uses a 32bit Alphanum-ish shellcode and bad chars detected are 00 2d 20.
Mitigation:
Ensure that the application is updated to the latest version and that all security patches are applied.