Executive brief
Hainsoft LanHelper, a network management tool for Windows, is vulnerable to a local buffer overflow. An attacker with access to the system can crash the application by inputting an excessively long string into the message field. This results in a denial-of-service condition, preventing the software from functioning correctly.
Technical details
A local buffer overflow vulnerability exists in Hainsoft LanHelper 1.74 due to improper bounds checking on input strings. Specifically, the 'Form Send Message' feature within the 'NT-Utilities' component fails to handle large data inputs. An attacker can trigger an out-of-bounds write (CWE-787) by pasting approximately 6000 bytes of data into the 'Message text' field. This leads to an application crash and a denial-of-service (DoS) condition. The vulnerability was verified on Windows XP SP3, and a public Proof of Concept (PoC) is available.
Affected products
- Hainsoft LanHelper 1.74
Timeline
- 2019-01-31: disclosed: Vulnerability discovered and PoC released on Exploit-DB
- 2026-04-05: advisory: NVD/VulnCheck advisory published