vendor:
Nsauditor
by:
Cervoise
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Nsauditor
Affected Version From: 3.0.28.0
Affected Version To: 3.2.1.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10.0.18363.778 x86 Pro EN
2020
Nsauditor 3.2.1.0 – Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
This exploit allows an attacker to bypass ASLR and SEH protections in Nsauditor version 3.2.1.0 and 3.0.28.0. By sending a specially crafted DNS query, an attacker can trigger a buffer overflow vulnerability and overwrite three bytes of memory. The exploit includes a customizable shellcode that can be used to execute arbitrary commands.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. In the meantime, users are advised to update to the latest version of Nsauditor and avoid opening untrusted DNS queries.