vendor:
VX Search Enterprise
by:
W01fier00t
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VX Search Enterprise
Affected Version From: 10.2.14
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 Home Edition sp1
2017
VX Search Enterprise v10.2.14 Buffer Overflow (SEH)
This exploit takes advantage of a buffer overflow vulnerability in VX Search Enterprise v10.2.14. The vulnerability allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code. The exploit requires enabling the web server and having login credentials for the VX Search webpage.
Mitigation:
Apply the latest patch or upgrade to a non-affected version of the software.