Executive brief
Remote Process Explorer is a tool used by administrators to monitor and manage processes on remote network computers. A vulnerability in the 'Add Computer' feature allows a user to crash the application by entering an excessively long computer name. This results in a denial of service, preventing the administrator from using the software to manage the network.
Technical details
A local buffer overflow exists in Lizardsystems Remote Process Explorer version 1.0.0.16. The vulnerability is located in the 'Add Computer' dialog's computer name input field, which fails to properly validate the length of the input string. By pasting a malicious payload (approximately 684 bytes) into this field and initiating a connection to the added entry, an attacker can overwrite the Structured Exception Handler (SEH) chain. While primarily documented as a denial of service (DoS) via application crash, the ability to overwrite the SEH chain suggests potential for local code execution. No patch is currently specified in the advisory.
Affected products
- Lizardsystems Remote Process Explorer 1.0.0.16
Timeline
- 2019-01-30: disclosed: Vulnerability discovered by Rafael Pedrero
- 2019-02-01: other: Exploit-DB PoC published
- 2026-04-05: advisory: NVD/VulnCheck advisory published