Executive brief
SpotDialup, a tool used for recovering dial-up and VPN passwords, contains a flaw that allows the application to be crashed. An attacker can trigger this by entering an excessively long registration key into the software's activation field. This results in a denial-of-service, preventing legitimate users from using the application on the affected machine.
Technical details
A classic buffer overflow (CWE-120) exists in SpotDialup 1.6.7 within the registration key input mechanism. The application fails to perform adequate bounds checking on the 'Key' field during the registration process. An attacker can trigger a crash by supplying a 1,000-character string, leading to a denial-of-service condition. While some metrics suggest a network vector, the exploit typically requires local interaction where a user or attacker pastes the malicious payload into the application's GUI on a Windows system. A public Proof of Concept (PoC) exists.
Affected products
- Nsasoft (NSAuditor) SpotDialup 1.6.7
Timeline
- 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
- 2026-02-11: advisory: NVD publication date