10-Strike Network Inventory Explorer Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in 10-Strike Network Inventory Explorer version 8.54. This vulnerability occurs in the structured exception handling (SEH) mechanism, allowing attackers to execute arbitrary code by overwriting SEH records. Exploitation involves crafting a malicious payload that targets the 'Computer' parameter in the 'Add' function.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Reproduction

To reproduce this vulnerability, first create a payload using a tool like msfvenom, specifying the desired command execution payload. Then, run a Python script that generates a buffer overflow payload, overwriting the SEH chain with a return address pointing to a 'pop' gadget in a vulnerable module. After copying this payload to the clipboard, paste it into the 'Computer' parameter under 'Computer Card' when adding a new entry. Once the payload is submitted, the injected code will be executed.

Added: Feb 5, 2026, 6:49 PM
Updated: Feb 5, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
2.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.