AgataSoft Auto PingMaster Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in AgataSoft Auto PingMaster version 1.5. The issue resides in the Trace Route host name field, where local attackers can execute arbitrary code by exploiting structured exception handling. By crafting a malicious ping.txt file containing shellcode and jump instructions, attackers can overwrite the SEH handler pointer. This manipulation allows the execution of injected code when the file contents are pasted into the application.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Reproduction

To reproduce this vulnerability, create a ping.txt file with shellcode and jump instructions designed to overwrite the Structured Exception Handling (SEH) handler pointer. Once the file is prepared, paste its contents into the Trace Route host name field within AgataSoft Auto PingMaster version 1.5. The application will execute the injected shellcode, demonstrating the buffer overflow vulnerability.

Added: May 26, 2026, 7:40 PM
Updated: May 26, 2026, 7:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.0
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.