vendor:
Net Resource
by:
s4squatch
9,3
CVSS
HIGH
SEH Overwrite
119
CWE
Product Name: Net Resource
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Magneto Software Net Resource ActiveX NetFileClose SEH Overwrite POC
The vulnerability exists in the SKNetResource.ocx ActiveX control, which is part of the Magneto Software Net Resource package. The vulnerability is caused due to a boundary error within the NetFileClose() method when handling user-supplied input. This can be exploited to cause a stack-based buffer overflow by supplying a specially crafted argument to the method. This may allow an attacker to execute arbitrary code.
Mitigation:
No mitigation or remediation is available for this vulnerability.