CVE-2018-6892
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 93%
from disclosure to weapon2 days
Published on NVDFeb 11
1st PoC+2d
metasploitJan 17
exploitation probability
93%top 1% of all CVEs
observed exploitation
nono source reports it
16 public exploit(s)
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Affected products
n/a · n/apublic PoCs found — 16✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44027exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44175exploitdbwww.exploit-db.com/exploits/46250unverifiedexploitdbwww.exploit-db.com/exploits/45197unverifiedgithubgithub.com/latortuga71/CVE-2018-6892-Golang★ 1githubgithub.com/manojcode/CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/manojcode/-Win10-x64-CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/crypticq/CLOUDME_B0F★ 0cve_referencepacketstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlunverifiedcve_referencepacketstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/45197/unverifiedcve_referencepacketstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/44175/unverifiedcve_referencewww.exploit-db.com/exploits/44027/unverifiedcve_referencewww.exploit-db.com/exploits/46250/unverifiedcve_referencewww.exploit-db.com/exploits/48840unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://hyp3rlinx.altervista.org/advisories/CLOUDME-SYNC-UNAUTHENTICATED-REMOTE-BUFFER-OVERFLOW.txthttp://packetstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlhttps://blogs.securiteam.com/index.php/archives/3669https://www.exploit-db.com/exploits/44027/https://www.exploit-db.com/exploits/44175/https://www.exploit-db.com/exploits/45197/https://www.exploit-db.com/exploits/46250/https://www.exploit-db.com/exploits/48840