vendor:
VX Search Enterprise
by:
Anurag Srivastava
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VX Search Enterprise
Affected Version From: 9.9.12
Affected Version To: 9.9.12
Patch Exists: YES
Related CWE: N/A
CPE: a:vxsearch:vx_search_enterprise:9.9.12
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Ultimate x64bit and Windows 10 Home Edition x64
2017
VX Search Enterprise v9.9.12 – ‘Import Command’ Buffer Overflow
VX Search Enterprise v9.9.12 is vulnerable to a buffer overflow vulnerability in the 'Import Command' feature. An attacker can exploit this vulnerability by creating a specially crafted XML file and importing it into the application. This will cause a buffer overflow and allow the attacker to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of VX Search Enterprise v9.9.12 or later.