Executive brief
BlueAuditor, a tool used for auditing and monitoring Bluetooth devices, is vulnerable to a flaw that allows a local user to crash the software. By entering an excessively long registration key during the activation process, an attacker can cause the application to stop responding. This results in a denial of service, preventing legitimate users from utilizing the software on the affected machine.
Technical details
A stack-based buffer overflow (CWE-787) exists in BlueAuditor version 1.7.2.0 within the registration key input processing component. The vulnerability is triggered when the application fails to properly validate the length of the string entered into the 'Key' field during the registration process. A local attacker can exploit this by providing a 256-byte or larger string of characters, leading to an out-of-bounds write that crashes the application process. This is a local attack requiring no special privileges or complex user interaction beyond the ability to input a registration key. A public proof-of-concept exploit is available.
Affected products
- Nsasoft BlueAuditor 1.7.2.0
Timeline
- 2019-01-04: other: Vulnerability discovered by Luis Martinez
- 2019-01-07: disclosed: Exploit-DB PoC published
- 2026-04-12: advisory: CVE published by VulnCheck