VX Search 10.6.18 - directory Local Buffer Overflow

Strike ID:
E18-0yby1
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2018

Description

This strike exploits a stack based buffer overflow vulnerability in VX Search 10.6.18. If a directory parameter is imported with an overly large amount of data, the stack can overflow allowing for remote code execution.