vendor:
ZOC Terminal
by:
chuyreds
7.8
CVSS
HIGH
Local
20
CWE
Product Name: ZOC Terminal
Affected Version From: 7.25.5
Affected Version To: 7.25.5
Patch Exists: YES
Related CWE: N/A
CPE: a:emtec:zoc_terminal:7.25.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
ZOC Terminal v7.25.5 – ‘Private key file’ Denial of Service (PoC)
A local denial of service vulnerability exists in ZOC Terminal v7.25.5 due to improper validation of user-supplied input. An attacker can exploit this vulnerability by running a specially crafted python code, copying the content of the generated file to clipboard, opening ZOC Terminal, selecting File > Create SSH Key Files..., selecting the 'Private key file:' field, erasing it and pasting the clipboard content, and clicking on 'Create public/private key files...' to crash the application.
Mitigation:
Upgrade to the latest version of ZOC Terminal.