nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6953 CVE-2017-6953
HIGH
Gemalto SmartDiag Diagnosis Tool < 2.5 - Local Buffer Overflow (SEH)
Record summary
CVE-2017-6953 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted input to SmartDiag.exe or SymDiag.exe.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGemalto SmartDiag Diagnosis Tool < 2.5 - Local Buffer Overflow (SEH)ExploitDB exploitby Majid AlqabandiNot analyzed1 file
References
241972exploit
https://www.exploit-db.com/exploits/41972