Description
Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges.
Problem types
Product status
Credits
Achilles
References
www.exploit-db.com/exploits/46005 (ExploitDB-46005)
www.nsauditor.com (Official Product Homepage)
www.nsauditor.com/downloads/nsauditor_setup.exe (Product Reference)
www.vulncheck.com/...ies/nsauditor-local-seh-buffer-overflow (VulnCheck Advisory: Nsauditor 3.0.28.0 Local SEH Buffer Overflow)