CVE-2020-37043
CRITICAL10-Strike Bandwidth Monitor 3.9 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37043. PoCs published by boku.
AI-analyzed exploit summary This exploit leverages a buffer overflow in 10-Strike Bandwidth Monitor 3.9 to bypass SEH, DEP, and ASLR using ROP chains, ultimately executing 'calc.exe' via WinExec. It demonstrates a reliable RCE by pivoting the stack and chaining gadgets from non-ASLR modules.
Description
10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through carefully crafted input. Attackers can exploit the vulnerability by sending a malicious payload to the application's registration key input, enabling remote code execution and launching arbitrary system commands.
Exploits (1)
This exploit leverages a buffer overflow in 10-Strike Bandwidth Monitor 3.9 to bypass SEH, DEP, and ASLR using ROP chains, ultimately executing 'calc.exe' via WinExec. It demonstrates a reliable RCE by pivoting the stack and chaining gadgets from non-ASLR modules.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H