Home

Description

10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string with 4188 bytes of padding followed by SEH chain values and shellcode, then paste it into the registration dialog to achieve code execution with application privileges.

PUBLISHED Reserved 2026-05-23 | Published 2026-05-23 | Updated 2026-05-26 | Assigner VulnCheck




HIGH: 8.6CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

Stack-based Buffer Overflow

Product status

8.54
affected

Credits

Hashim Jawad - ihack4falafelx finder

References

www.exploit-db.com/exploits/44840 (ExploitDB-44840) exploit

www.10-strike.com/ (Official Product Homepage) product

www.vulncheck.com/...-inventory-explorer-buffer-overflow-seh (VulnCheck Advisory: 10-Strike Network Inventory Explorer 8.54 Buffer Overflow SEH) third-party-advisory

cve.org (CVE-2018-25344)

nvd.nist.gov (CVE-2018-25344)

Download JSON