There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability by sending crafted messages to computers installed with this plug-in, which could lead to arbitrary code execution or cause process exception of the plug-in.
The vulnerability consists of a buffer overflow in the browser plugin code. An attacker sends specially crafted messages to a computer with the installed plugin, causing the memory buffer boundaries to be exceeded. As a result, it is possible to overwrite critical data structures in the process memory, leading to arbitrary code execution (RCE) or triggering an exception and plugin process crash.
An attacker can remotely execute arbitrary code on the victim's computer (RCE) or cause the browser plugin process to crash, resulting in loss of availability. The vulnerability also enables compromise of the confidentiality of data processed by the application.
Security patches available from the vendor should be applied according to references — detailed information about updated plugin versions is available in the Hikvision security bulletin at the address indicated in the references.
Computers with the Hikvision LocalServiceComponents web browser plugin installed; specific versions indicated in the vendor's references.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HHikvision Localservicecomponents
APPHikvision≤ 1.0.0.78
Related vulnerabilities
An attacker could exploit a vulnerability by sending crafted messages to computers installed with this plug-in...
Command injection w serwerze WWW kamer Hikvision (nieautoryzowany RCE)
Hikvision IP Camera — ominięcie uwierzytelnienia (Auth Bypass)
Podatność kontroli dostępu w Hikvision Hybrid SAN/Cluster Storage
Hikvision Wireless Bridge – podatność access control w serwerze web