CVE-2020-37142

8.4

10-Strike Software · Network Inventory Explorer

10-Strike Network Inventory Explorer 8.54 is vulnerable to a stack-based buffer overflow via the Computer parameter, allowing unauthenticated local attackers to execute arbitrary code.

Executive summary

A critical stack-based buffer overflow vulnerability in 10-Strike Network Inventory Explorer 8.54 allows for potential remote code execution via malicious input.

Vulnerability

The application is susceptible to a stack-based buffer overflow through improper handling of structured exception handler (SEH) records. By injecting a crafted payload into the Computer parameter during the Add function, an attacker can overwrite the SEH chain and achieve arbitrary code execution.

Business impact

The vulnerability carries a high CVSS score of 8.4, reflecting the significant risk of full system compromise. Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the application, potentially leading to unauthorized data access, system instability, or the installation of persistent malicious software.

Remediation

Immediate Action: Upgrade to the latest version of 10-Strike Network Inventory Explorer provided by the vendor, as this version is confirmed vulnerable.

Proactive Monitoring: Review system logs for unusual application crashes or repeated exception events associated with the Network Inventory Explorer processes, which may indicate exploitation attempts.

Compensating Controls: Ensure that the application is running with the least privilege necessary and restrict access to the host machine to authorized personnel only, as this is a local attack vector.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via the Exploit Database (EDB-ID 48253) and associated researcher technical documentation.

Analyst recommendation

Given the potential for arbitrary code execution and the availability of public exploit material, this vulnerability should be treated with high urgency. Administrators are advised to apply the vendor-supplied security updates immediately to mitigate the risk of exploitation.

Sources

Originally found and disclosed by Felipe Winsnes, per the CVE Program record.