CVE-2024-0771

MEDIUM

Nsasoft Product Key Explorer <4.0.9 - Memory Corruption

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.251671
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.251671
Exploit exploit media-coverage
https://youtu.be/eecN5mC0avU

Scores

CVSS v3 5.3
EPSS 0.0030
EPSS Percentile 22.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-787
Status published
Products (1)
nsasoft/product_key_explorer 4.0.9
Published Jan 21, 2024
Tracked Since Feb 18, 2026