vendor:
ServersCheck Monitoring Software
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
Denial of Service
22
CWE
Product Name: ServersCheck Monitoring Software
Affected Version From: 14.3.3
Affected Version To: 14.3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:serverscheck:serverscheck_monitoring_software
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2018
ServersCheck Monitoring Software 14.3.3 – Denial of Service (PoC)
ServersCheck Monitoring Software allows remote attackers to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu item. Ultimately, this behavior comes from a Directory Traversal bug (via the sensor_details.html id parameter) that allows creating empty files in arbitrary directories.
Mitigation:
Vendor released patch on October 23, 2018