DeviceLock Plug and Play Auditor Unicode Buffer Overflow

Strike ID:
E18-5i3j1
CVSS:
7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2018

Description

This strike exploits a buffer overflow vulnerability in DeviceLock Plug and Play Auditor. The vulnerability is due to improper parsing of the file used to import hosts to be scanned. By enticing a user to import a specially crafted file, an attacker could potentially run arbitrary code on the target system.

CVE