DameWare Mini Remote Control Pre-Authentication Remote Overflow

critical Nessus Plugin ID 19553

Synopsis

Arbitrary code can be executed on the remote host.

Description

The remote host is running DameWare Mini Remote Control. The remote version of this software is affected by a buffer overflow vulnerability.

An attacker may be able to exploit this flaw by sending a specially crafted packet to the remote host.

A successful exploitation of this vulnerability would result in remote code execution.

Solution

Upgrade to version 3.73.0.0 or later

Plugin Details

Severity: Critical

ID: 19553

File Name: dameware_mini_remote_control_overflow.nasl

Version: 1.21

Type: remote

Agent: windows

Family: Windows

Published: 9/1/2005

Updated: 7/6/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:dameware:mini_remote_control

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 12/16/2003

Exploitable With

Core Impact

ExploitHub (EH-11-317)

Reference Information

CVE: CVE-2003-1030

BID: 9213