Lucene search

K
zdiAnonymousZDI-14-160
HistoryJun 02, 2014 - 12:00 a.m.

(0Day) Ericom AccessNow Server Stack Buffer Overflow Remote Code Execution Vulnerability

2014-06-0200:00:00
Anonymous
www.zerodayinitiative.com
21

EPSS

0.877

Percentile

98.7%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Ericom AccessNow Server. Authentication is not required to exploit this vulnerability. The specific flaw exists in the way AccessServer32.exe handles requests for non-existent files. AccessServer32.exe performs insufficient bounds checking on user-supplied data which results in stack corruption. An attacker can exploit this condition to achieve remote code execution as SYSTEM.