CVE-2018-25268
HIGHLanSpy 2.0.1.159 Local Buffer Overflow via Scan Field
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25268. PoCs published by Gionathan Reale.
AI-analyzed exploit summary This Python script generates a buffer overflow payload targeting LanSpy 2.0.1.159. It creates a 688-byte buffer followed by a 4-byte EIP overwrite, which is written to 'exploit.txt' for manual execution in the vulnerable application.
Description
LanSpy 2.0.1.159 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying oversized input to the scan field. Attackers can craft a payload with 688 bytes of padding followed by 4 bytes of controlled data to crash the application or potentially achieve code execution.
Exploits (1)
This Python script generates a buffer overflow payload targeting LanSpy 2.0.1.159. It creates a 688-byte buffer followed by a 4-byte EIP overwrite, which is written to 'exploit.txt' for manual execution in the vulnerable application.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H