CVE-2021-47814

7.5

Nsauditor · NBMonitor

NBMonitor version 1.6.8 is susceptible to a buffer overflow vulnerability in the registration code input field, which can lead to a local denial of service and application instability.

Executive summary

A buffer overflow vulnerability in Nsauditor NBMonitor 1.6.8 allows local attackers to crash the application, resulting in a denial of service.

Vulnerability

The application fails to perform adequate bounds checking on the registration key input field, allowing a 256 character buffer to trigger a crash. This vulnerability requires local user interaction to trigger.

Business impact

The vulnerability poses a risk to system stability and availability for users of the NBMonitor software. While the CVSS score of 7.5 reflects a high severity due to the impact on application availability, the requirement for local access limits the scope of the threat in enterprise environments. Successful exploitation results in an immediate application crash, causing potential loss of unsaved work or temporary service disruption.

Remediation

Immediate Action: As no patch is currently available, users should restrict access to the application registration interface and avoid entering untrusted registration codes.

Proactive Monitoring: Security teams should monitor system event logs for repeated application crashes or unexpected service termination associated with the NBMonitor process.

Compensating Controls: Implement local endpoint security policies to restrict unauthorized users from accessing sensitive application configuration menus.

Exploitation status

Public Exploit Available: Yes, a proof of concept is available via ExploitDB (EDB-ID: 49964).

Analyst recommendation

Given the availability of a public proof of concept, administrators should treat this vulnerability as a credible risk to workstation or server stability. Until the vendor provides a security update, organizations should ensure that only authorized personnel have the ability to interact with the registration features of the software to prevent accidental or malicious exploitation.

More Nsauditor CVEs

Sources

Originally found and disclosed by Erick Galindo, per the CVE Program record.