10-Strike Network Inventory Explorer Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in 10-Strike Network Inventory Explorer version 8.65. This vulnerability arises in the exception handling process, allowing remote attackers to execute arbitrary code. Exploitation involves crafting a malicious file that includes 209 bytes of padding and a specially designed Structured Exception Handler to trigger the code execution.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the affected system.

Reproduction

The vulnerability can be reproduced by creating a file that includes 209 bytes of padding followed by a crafted Structured Exception Handler. When this file is opened with 10-Strike Network Inventory Explorer 8.65, the buffer overflow occurs, and the padded bytes can be used to overwrite the return address on the stack, redirecting execution to the attacker's payload.

Added: Jan 28, 2026, 6:45 PM
Updated: Jan 28, 2026, 6:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.