PT-2019-16804 · Dameware · Dameware Mini Remote Control
Publicado
2019-06-07
·
Atualizado
2020-08-24
·
CVE-2019-3955
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Dameware Remote Mini Control versions 12.1.0.34 and prior
Description
The issue is caused by the server not properly validating
RsaPubKeyLen during key negotiation, leading to an unauthenticated remote heap overflow. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, potentially resulting in a denial of service.Recommendations
For Dameware Remote Mini Control versions 12.1.0.34 and prior, update to a version that fixes the
RsaPubKeyLen validation issue to prevent the heap buffer overflow.
As a temporary workaround, consider restricting access to the key negotiation process to minimize the risk of exploitation.Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dameware Mini Remote Control