Executive brief
10-Strike Network Inventory Explorer is a software tool used by IT administrators to track hardware and software assets across a corporate network. A security flaw in the software's registration process allows a local user to crash the application and run unauthorized commands. If exploited, an attacker could gain full control over the system where the software is installed, potentially leading to data theft or further network compromise.
Technical details
A stack-based buffer overflow vulnerability exists in 10-Strike Network Inventory Explorer version 8.54 and potentially earlier versions. The flaw is located in the 'Registration Key' input field within the registration dialog. By providing a specially crafted string exceeding 4188 bytes, an attacker can trigger a Structured Exception Handler (SEH) overwrite. This allows for the redirection of the execution flow to attacker-controlled shellcode. The attack is local in nature, requiring the attacker to have access to the application's interface to paste the malicious key. Successful exploitation results in arbitrary code execution with the privileges of the application. No official patch has been confirmed by the vendor.
Affected products
- 10-Strike Network Inventory Explorer 8.54 and earlier
Timeline
- 2018-06-02: other: Initial vendor contact by researcher
- 2018-06-05: disclosed: Proof of concept exploit published on Exploit-DB
- 2026-05-23: advisory: CVE-2018-25344 published/updated in NVD