PT-2019-16804 · Dameware · Dameware Mini Remote Control
Published
2019-06-07
·
Updated
2020-08-24
·
CVE-2019-3955
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Dameware Remote Mini Control versions 12.1.0.34 and prior
Description
The issue is caused by the server not properly validating
RsaPubKeyLen during key negotiation, leading to an unauthenticated remote heap overflow. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, potentially resulting in a denial of service.Recommendations
For Dameware Remote Mini Control versions 12.1.0.34 and prior, update to a version that fixes the
RsaPubKeyLen validation issue to prevent the heap buffer overflow.
As a temporary workaround, consider restricting access to the key negotiation process to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dameware Mini Remote Control