CVE-2020-36943
7.5aSc (Applied Software Consultants) · TimeTables
aSc TimeTables 2021.6.2 is vulnerable to a denial of service attack where an attacker can crash the application by injecting an excessively large string into the subject title field.
Executive summary
A heap-based resource exhaustion vulnerability in aSc TimeTables 2021.6.2 allows local attackers to cause application instability and crashes.
Vulnerability
The application fails to implement proper input validation or resource throttling on the subject title field, allowing an attacker to trigger a crash via a 10,000 character buffer overflow. This vulnerability can be exploited by an unauthenticated local user who has access to the application interface.
Business impact
The successful exploitation of this vulnerability results in a denial of service, rendering the application unusable for authorized users. While the CVSS score of 7.5 reflects a high severity due to the potential for complete application failure, the impact is localized to the affected workstation. This can lead to operational disruptions in academic or administrative environments relying on the software for scheduling.
Remediation
Immediate Action: As no official patch is currently available, administrators should restrict access to the application to trusted users only and avoid entering untrusted or excessively long data into subject fields.
Proactive Monitoring: Monitor local system logs for application crash events associated with the aSc TimeTables executable.
Compensating Controls: Implement endpoint security policies that restrict unauthorized software modifications and ensure the principle of least privilege is applied to users on shared workstations.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via ExploitDB (EDB-ID 49147).
Analyst recommendation
Given the availability of a public proof of concept and the relative ease of triggering a crash, users should exercise caution when inputting data into the software. Organizations should prioritize migrating to a supported version if one becomes available or evaluate the necessity of the software in environments where high availability is required.
More aSc (Applied Software Consultants) CVEs
Sources
Originally found and disclosed by Ismael Nava, per the CVE Program record.
- ExploitDB-49147 Exploit / PoC
- Vendor Homepage
- Software Download Page
- VulnCheck Advisory: aSc TimeTables 2021.6.2 - Denial of Service Third-party advisory