CVE-2020-37119
CRITICALNsasoft Nsauditor 3.0.28 and 3.2.1.0 - Stack-based Buffer Overflow via DNS Lookup Tool
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37119. PoCs published by Cervoise.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Nsauditor 3.2.1.0 and 3.0.28, leveraging SEH overwrite and ASLR bypass to achieve remote code execution via a crafted DNS query input. The payload includes shellcode and a custom egghunter-like mechanism to navigate memory constraints.
Description
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed exploit.
Exploits (1)
This exploit demonstrates a buffer overflow vulnerability in Nsauditor 3.2.1.0 and 3.0.28, leveraging SEH overwrite and ASLR bypass to achieve remote code execution via a crafted DNS query input. The payload includes shellcode and a custom egghunter-like mechanism to navigate memory constraints.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H