10-Strike Network Inventory Explorer
cpe:2.3:a:10-strike:network_inventory_explorer:*:*:*:*:*:*:*
- 8.54
A buffer overflow vulnerability has been identified in 10-Strike Network Inventory Explorer version 8.54. This vulnerability occurs in the structured exception handling (SEH) mechanism, allowing attackers to execute arbitrary code by overwriting SEH records. Exploitation involves crafting a malicious payload that targets the 'Computer' parameter in the 'Add' function.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
To reproduce this vulnerability, first create a payload using a tool like msfvenom, specifying the desired command execution payload. Then, run a Python script that generates a buffer overflow payload, overwriting the SEH chain with a return address pointing to a 'pop' gadget in a vulnerable module. After copying this payload to the clipboard, paste it into the 'Computer' parameter under 'Computer Card' when adding a new entry. Once the payload is submitted, the injected code will be executed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.