Description
LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe or other arbitrary commands.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Dino Covotsos - Telspace Systems
References
www.exploit-db.com/exploits/46737 (ExploitDB-46737)
www.labf.com/nfsaxe (Official Product Homepage)
www.vulncheck.com/...labf-nfsaxe-ping-client-buffer-overflow (VulnCheck Advisory: LabF nfsAxe 3.7 Ping Client Buffer Overflow)