1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 |
[+] Title: Disk Sorter Server v9.5.12 - Local Stack-based buffer overflow [+] Credits / Discovery: Nassim Asrir [+] Author Email: wassline@gmail.com || https://www.linkedin.com/in/nassim-asrir-b73a57122/ [+] Author Company: Henceforth [+] CVE: N/A Vendor: =============== http://www.disksorter.com/ Download: =========== http://www.disksorter.com/setups/disksortersrv_setup_v9.5.12.exe Vulnerability Type: =================== local stack-based buffer overflow POC: =================== Launch the program click on : 1 - Server 2 - Connect 3 - and in the Share Name field inject (5000 "A") then the program crashed see the picture. CVE Reference: =============== N/A Tested on: =============== Windows 7 Win xp |