Executive brief
10-Strike LANState, a network mapping and management tool for administrators, is vulnerable to a security flaw that allows an attacker to take control of a computer. By tricking a user into opening a specially crafted map file (.LSM), an attacker can execute malicious code on the system. This could lead to a complete compromise of the administrator's workstation and potential disruption of network monitoring operations.
Technical details
A local buffer overflow vulnerability exists in 10-Strike LANState 8.8 due to improper bounds checking when parsing LSM map files. Specifically, a long string provided in the 'ObjCaption' parameter can trigger an out-of-bounds write (CWE-787), allowing an attacker to overwrite the Structured Exception Handler (SEH) chain. To exploit this, an attacker must provide a victim with a maliciously crafted .LSM file; when the application opens the file, the overwritten SEH leads to the execution of arbitrary shellcode. While the attack requires local file interaction, it does not require prior administrative privileges within the application itself.
Affected products
- 10-Strike LANState 8.8
Timeline
- 2018-07-24: disclosed: Original exploit author disclosure
- 2026-04-04: advisory: NVD publication date