CVE-2018-6892
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Affected products
n/a · n/apublic PoCs found — 16
githubgithub.com/latortuga71/CVE-2018-6892-Golang★ 1githubgithub.com/manojcode/CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/manojcode/-Win10-x64-CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/crypticq/CLOUDME_B0F★ 0cve_referencewww.exploit-db.com/exploits/44175/unverifiedcve_referencewww.exploit-db.com/exploits/45197/unverifiedcve_referencewww.exploit-db.com/exploits/46250/unverifiedcve_referencewww.exploit-db.com/exploits/48840unverifiedexploitdbwww.exploit-db.com/exploits/44175unverifiedexploitdbwww.exploit-db.com/exploits/44027unverifiedexploitdbwww.exploit-db.com/exploits/45197unverifiedcve_referencepacketstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlunverifiedexploitdbwww.exploit-db.com/exploits/46250unverifiedcve_referencepacketstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlunverifiedcve_referencepacketstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/44027/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://hyp3rlinx.altervista.org/advisories/CLOUDME-SYNC-UNAUTHENTICATED-REMOTE-BUFFER-OVERFLOW.txthttp://packetstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlhttps://blogs.securiteam.com/index.php/archives/3669https://www.exploit-db.com/exploits/44027/https://www.exploit-db.com/exploits/44175/https://www.exploit-db.com/exploits/45197/https://www.exploit-db.com/exploits/46250/https://www.exploit-db.com/exploits/48840