CVE-2018-6892
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Productos afectados
n/a · n/aPoCs públicas encontradas — 16
githubgithub.com/latortuga71/CVE-2018-6892-Golang★ 1githubgithub.com/manojcode/CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/manojcode/-Win10-x64-CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/crypticq/CLOUDME_B0F★ 0cve_referencewww.exploit-db.com/exploits/44175/no verificadocve_referencewww.exploit-db.com/exploits/45197/no verificadocve_referencewww.exploit-db.com/exploits/46250/no verificadocve_referencewww.exploit-db.com/exploits/48840no verificadoexploitdbwww.exploit-db.com/exploits/44175no verificadoexploitdbwww.exploit-db.com/exploits/44027no verificadoexploitdbwww.exploit-db.com/exploits/45197no verificadocve_referencepacketstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlno verificadoexploitdbwww.exploit-db.com/exploits/46250no verificadocve_referencepacketstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlno verificadocve_referencepacketstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlno verificadocve_referencewww.exploit-db.com/exploits/44027/no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://hyp3rlinx.altervista.org/advisories/CLOUDME-SYNC-UNAUTHENTICATED-REMOTE-BUFFER-OVERFLOW.txthttp://packetstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlhttps://blogs.securiteam.com/index.php/archives/3669https://www.exploit-db.com/exploits/44027/https://www.exploit-db.com/exploits/44175/https://www.exploit-db.com/exploits/45197/https://www.exploit-db.com/exploits/46250/https://www.exploit-db.com/exploits/48840