Nsauditor Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in Nsauditor version 3.2.2.0. This vulnerability allows attackers to crash the application by overwriting the Event Description field with a large buffer. By generating a 10,000-character 'U' buffer and pasting it into the Event Description field, the application can be forced to crash.
Impact
Exploitation of this vulnerability leads to a crash of the Nsauditor application, causing a denial-of-service condition where the application becomes unresponsive or unavailable.
Reproduction
To reproduce this vulnerability, open Nsauditor 3.2.2.0 on a Windows 10 Home x64 system. Navigate to the Options menu and select Configuration, then click on Security Events. Run the provided Python exploit script, which will create a text file containing the 10,000-character 'U' buffer. Copy the contents of this file and paste it into the Event Description field. Click 'Add Event' to trigger the application crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
