Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application.
Metrics
Affected Vendors & Products
References
History
Sat, 04 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Sat, 04 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application. | Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application. |
| Title | Microsoft Smart VPN 1.1.3.0 Denial of Service via Search | Smart VPN 1.1.3.0 Denial of Service via Search |
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application. | |
| Title | Microsoft Smart VPN 1.1.3.0 Denial of Service via Search | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-04T13:51:07.117Z
Updated: 2026-04-04T19:59:50.982Z
Reserved: 2026-04-04T13:16:20.974Z
Link: CVE-2018-25239
No data.
Status : Received
Published: 2026-04-04T14:16:19.293
Modified: 2026-04-04T20:16:17.320
Link: CVE-2018-25239
No data.