Arm Whois 3.11 Buffer Overflow via SEH Overwrite
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception handler and gain command execution when the application processes the input.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Armcode · Arm Whoispublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/45796unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.