ID:1353 - Exploit for Memory corruption in OfficeScan - CVE-2017-14089

 
Main Vulnerability Database Exploits ID:1353 - Exploit for Memory corruption in OfficeScan - CVE-2017-14089

ID:1353 - Exploit for Memory corruption in OfficeScan - CVE-2017-14089

Published: March 18, 2020


Vulnerability identifier: #VU8809
Vulnerability risk: Medium
CVE-ID: CVE-2017-14089
CWE-ID: CWE-119
Exploitation vector: Remote access
Vulnerable software:
OfficeScan

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper validation of user request in cgiShowClientAdm.exe. A remote attacker can send a specially crafted request, trigger memory corruption and cause the system to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Install updated versions from vendor's website.