PT-2019-16804 · Dameware · Dameware Mini Remote Control

Published

2019-06-07

·

Updated

2020-08-24

·

CVE-2019-3955

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dameware Remote Mini Control versions 12.1.0.34 and prior
Description The issue is caused by the server not properly validating RsaPubKeyLen during key negotiation, leading to an unauthenticated remote heap overflow. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, potentially resulting in a denial of service.
Recommendations For Dameware Remote Mini Control versions 12.1.0.34 and prior, update to a version that fixes the RsaPubKeyLen validation issue to prevent the heap buffer overflow. As a temporary workaround, consider restricting access to the key negotiation process to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3955

Affected Products

Dameware Mini Remote Control