Description
Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Device alias field within the Managing Log interface to execute arbitrary code with calculator proof-of-concept execution.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45492 (ExploitDB-45492)
support.faleemi.com/fsc776/Faleemi_v1.8.exe (Product Reference)
www.vulncheck.com/...ktop-software-local-buffer-overflow-seh (VulnCheck Advisory: Faleemi Desktop Software 1.8.2 Local Buffer Overflow SEH)