PT-2019-13163 · Naver · Naver Cloud Explorer+1

F10W3R

+1

·

Publicado

2019-09-03

·

Atualizado

2020-10-08

·

CVE-2019-13156

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Naver Cloud Explorer version 1.2.2
Description The issue is related to a stack-based buffer overflow in the NDrive(1.2.2).sys component. This overflow occurs when reading data from an IOCTL handle, allowing attackers to cause a denial of service.
Recommendations For version 1.2.2, consider restricting access to the NDrive(1.2.2).sys component until a patch is available. As a temporary workaround, avoid using the IOCTL handle that triggers the buffer overflow to minimize the risk of exploitation.

Correção

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13156

Produtos afetados

Ndrive.Sys
Naver Cloud Explorer