Description
Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
0xMoHassan
References
www.exploit-db.com/exploits/48284 (ExploitDB-48284)
www.nsauditor.com (Vendor Homepage)
www.vulncheck.com/...duct-key-explorer-key-denial-of-service (VulnCheck Advisory: Product Key Explorer 4.2.2.0 - 'Key' Denial of Service)