CVE-2020-37142
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-121
Desbordamiendo de búfer basado en pila (Stack)
Fecha de publicación:
05/02/2026
Última modificación:
05/02/2026
Descripción
*** Pendiente de traducción *** 10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code execution.
Impacto
Puntuación base 4.0
8.40
Gravedad 4.0
ALTA
Puntuación base 3.x
8.40
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://web.archive.org/web/20210105222137/https://whitecr0wz.github.io/posts/Strike-Network-Inventory-Explorer-Structered-Exception-Handling-Overwrite/
- https://www.10-strike.com/
- https://www.exploit-db.com/exploits/48253
- https://www.vulncheck.com/advisories/strike-network-inventory-explorer-add-local-buffer-overflow-seh



