10-Strike Network Inventory Explorer
cpe:2.3:a:10-strike:network_inventory_explorer:*:*:*:*:*:*:*
- 8.65
A buffer overflow vulnerability has been identified in 10-Strike Network Inventory Explorer version 8.65. This vulnerability arises in the exception handling process, allowing remote attackers to execute arbitrary code. Exploitation involves crafting a malicious file that includes 209 bytes of padding and a specially designed Structured Exception Handler to trigger the code execution.
Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the affected system.
The vulnerability can be reproduced by creating a file that includes 209 bytes of padding followed by a crafted Structured Exception Handler. When this file is opened with 10-Strike Network Inventory Explorer 8.65, the buffer overflow occurs, and the padded bytes can be used to overwrite the return address on the stack, redirecting execution to the attacker's payload.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.