CVE-2018-25345
HIGH10-Strike Network Scanner 3.0 Local Buffer Overflow SEH
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25345. PoCs published by Hashim Jawad.
AI-analyzed exploit summary This exploit demonstrates a local buffer overflow vulnerability in 10-Strike Network Scanner 3.0, leveraging SEH overwrite to achieve remote code execution via a bind shell payload. The exploit bypasses SafeSEH protections and uses a custom ROP chain to redirect execution flow.
Description
10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in the host name field that allows attackers to bypass SafeSEH protections and execute arbitrary code. Attackers can craft a malicious payload in the host name or address field and trigger the vulnerability through the Trace route or System information functions to achieve code execution.
Exploits (1)
This exploit demonstrates a local buffer overflow vulnerability in 10-Strike Network Scanner 3.0, leveraging SEH overwrite to achieve remote code execution via a bind shell payload. The exploit bypasses SafeSEH protections and uses a custom ROP chain to redirect execution flow.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H