CVE-2019-25661
MEDIUMRemote Process Explorer 1.0.0.16 Local Buffer Overflow DoS
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25661. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary This Python script generates a malicious input file that triggers a local buffer overflow in Remote Process Explorer v1.0.0.16, leading to a Denial of Service (DoS) and SEH overwriting. The exploit demonstrates the vulnerability by crafting a payload that crashes the application when pasted into the 'Add computer' field.
Description
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer, overwriting the SEH chain and corrupting exception handlers.
Exploits (1)
This Python script generates a malicious input file that triggers a local buffer overflow in Remote Process Explorer v1.0.0.16, leading to a Denial of Service (DoS) and SEH overwriting. The exploit demonstrates the vulnerability by crafting a payload that crashes the application when pasted into the 'Add computer' field.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H