vendor:
LanSpy.exe
by:
hyp3rlinx
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: LanSpy.exe
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: lantricks:lanspy
Platforms Tested:
2015
LanSpy Buffer Overflow Vulnerability
LanSpy.exe is prone to a buffer overflow vulnerability. This vulnerability occurs when a malicious 'addresses.txt' file is loaded by the application. The payload for the buffer overflow must be the very first entry in the text file. When the application is run and the scanning process is initiated, the program crashes, allowing an attacker to control the EIP at 684 bytes and overwrite both the NSEH & SEH exception handler pointers.
Mitigation:
There is no known mitigation or remediation for this vulnerability.