Description
10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code execution.
Problem types
Product status
Credits
Felipe Winsnes
References
www.exploit-db.com/exploits/48253 (ExploitDB-48253)
www.10-strike.com/ (10-Strike Software Homepage)
web.archive.org/...-Structered-Exception-Handling-Overwrite/ (Archived Researcher Blog)
www.vulncheck.com/...-explorer-add-local-buffer-overflow-seh (VulnCheck Advisory: 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH))