Description
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer, overwriting the SEH chain and corrupting exception handlers.
Problem types
Product status
Credits
Rafael Pedrero
References
www.exploit-db.com/exploits/46304 (ExploitDB-46304)
lizardsystems.com/...ome&product=rpexplorer&version=1.0.0.16 (Official Product Homepage)
www.vulncheck.com/...cess-explorer-local-buffer-overflow-dos (VulnCheck Advisory: Remote Process Explorer 1.0.0.16 Local Buffer Overflow DoS)