Executive brief
ShareAlarmPro, a network access control and security auditing tool, is vulnerable to a flaw that can cause the application to crash. An attacker can trigger this by entering an excessively long registration key into the software's activation field. This results in a denial-of-service, preventing legitimate users from using the security software to monitor their network.
Technical details
A classic buffer overflow (CWE-120) exists in ShareAlarmPro Advanced Network Access Control within the registration key input field. The application fails to perform adequate bounds checking on the input length before copying it into a fixed-size buffer. An attacker can exploit this by providing a registration key approximately 1,000 characters long, leading to memory corruption and an immediate application crash (Denial of Service). While the attack requires local interaction to paste the key, it does not require prior authentication. A public Proof of Concept (PoC) exists, but no official patch has been confirmed in the advisory.
Affected products
- Nsasoft (NSAuditor) ShareAlarmPro Advanced Network Access Control All versions (up to and including 2020 releases)
Timeline
- 2020-01-06: disclosed: Initial exploit PoC published to Exploit-DB
- 2026-02-11: advisory: NVD/VulnCheck advisory published