Description
NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigger code execution when the Find function is invoked.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Peyman Forouzan
References
www.exploit-db.com/exploits/46578 (ExploitDB-46578)
netsharewatcher.nsauditor.com (Official Product Homepage)
netsharewatcher.nsauditor.com/...s/NetShareWatcher_setup.exe (Product Reference)
www.vulncheck.com/...ies/netsharewatcher-seh-buffer-overflow (VulnCheck Advisory: NetShareWatcher 1.5.8.0 SEH Buffer Overflow)