Executive brief
Nsasoft RemShutdown, a tool used for remote computer management and shutdown tasks, contains a flaw in its registration system. An attacker can cause the application to crash and become unavailable by entering an excessively long string of characters into the 'Name' registration field. This results in a denial-of-service condition, preventing legitimate users from using the software.
Technical details
A classic buffer overflow (CWE-120) exists in Nsasoft RemShutdown version 2.9.0.0. The vulnerability is located in the 'Name' field of the 'Enter Registration Code' dialog, which fails to properly validate the length of user-supplied input. An attacker can trigger the vulnerability by pasting a buffer of approximately 1,000 characters into the field and clicking 'Ok', leading to an application crash (Denial of Service). While some CVSS vectors suggest a network vector, the primary exploit method involves local user interaction with the registration interface. No official patch has been identified in the advisory.
Affected products
- Nsasoft (NSAuditor) RemShutdown 2.9.0.0
Timeline
- 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
- 2026-02-11: advisory: NVD/VulnCheck advisory published