vendor:
NBMonitor
by:
Erick Galindo
7.8
CVSS
HIGH
Denial of Service
119
CWE
Product Name: NBMonitor
Affected Version From: 1.6.8
Affected Version To: 1.6.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:nsauditor:nbmonitor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2021
NBMonitor 1.6.8 – Denial of Service (PoC)
A denial of service vulnerability exists in NBMonitor 1.6.8 due to a buffer overflow when a crafted string of 256 A's is copied to the clipboard and pasted into the 'Key' field when registering the software. This causes the application to crash.
Mitigation:
Upgrade to the latest version of NBMonitor.