Description
10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through carefully crafted input. Attackers can exploit the vulnerability by sending a malicious payload to the application's registration key input, enabling remote code execution and launching arbitrary system commands.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Bobby Cooke
References
www.exploit-db.com/exploits/48570 (ExploitDB-48570)
www.10-strike.com/bandwidth-monitor/ (Product Webpage)
www.vulncheck.com/...trike-bandwidth-monitor-buffer-overflow (VulnCheck Advisory: 10-Strike Bandwidth Monitor 3.9 - Buffer Overflow)