vendor:
VXSearch
by:
wetw0rk
5.5
CVSS
MEDIUM
Local Buffer Overflow
119
CWE
Product Name: VXSearch
Affected Version From: 10.2.14
Affected Version To: 10.2.14
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 (x86)
2017
VXSearch v10.2.14 Local SEH Overflow
VX Search v10.2.14 suffers from a local buffer overflow. The following exploit will generate a bind shell on port 1337. I was unable to get a shell working with msfvenom shellcode so below is a custom alphanumeric bind shell.
Mitigation:
Update to the latest version