Impact
NetShareWatcher 1.5.8.0 contains a structured exception handler (SEH) buffer overflow that can be triggered by a local attacker using a crafted input in the Restrictions custom filter field. By overwriting the SEH and NSEH pointers, the attacker can cause arbitrary code execution when the Find function processes that input. The result is full compromise of the affected system, allowing the attacker to read, modify or delete data, establish persistence or pivot to other assets.
Affected Systems
The vulnerability affects the NetShareWatcher product from nsauditor, specifically version 1.5.8.0. No other versions or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity and the vulnerability can be exploited by local users who have permission to supply input to the application’s filtering feature. Since the EPSS score is not available and the vulnerability is not present in the CISA KEV catalog, a massive, widespread exploitation is not presently evident, but a local attacker can achieve full system compromise through the vulnerable Find function. An exploit is available in public resources, confirming the practical risk for systems running the affected software.
OpenCVE Enrichment