Vulnerability Description
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer, overwriting the SEH chain and corrupting exception handlers.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- http://lizardsystems.com/action.php?action=home&product=rpexplorer&version=1.0.0
- https://www.exploit-db.com/exploits/46304
- https://www.vulncheck.com/advisories/remote-process-explorer-local-buffer-overfl
FAQ
What is CVE-2019-25661?
CVE-2019-25661 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers ca...
How severe is CVE-2019-25661?
CVE-2019-25661 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25661?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.