CVE-2018-6892
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 16
githubgithub.com/latortuga71/CVE-2018-6892-Golang★ 1githubgithub.com/manojcode/CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/manojcode/-Win10-x64-CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass★ 0githubgithub.com/crypticq/CLOUDME_B0F★ 0cve_referencewww.exploit-db.com/exploits/44175/não verificadocve_referencewww.exploit-db.com/exploits/45197/não verificadocve_referencewww.exploit-db.com/exploits/46250/não verificadocve_referencewww.exploit-db.com/exploits/48840não verificadoexploitdbwww.exploit-db.com/exploits/44175não verificadoexploitdbwww.exploit-db.com/exploits/44027não verificadoexploitdbwww.exploit-db.com/exploits/45197não verificadocve_referencepacketstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/46250não verificadocve_referencepacketstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlnão verificadocve_referencepacketstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlnão verificadocve_referencewww.exploit-db.com/exploits/44027/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://hyp3rlinx.altervista.org/advisories/CLOUDME-SYNC-UNAUTHENTICATED-REMOTE-BUFFER-OVERFLOW.txthttp://packetstormsecurity.com/files/157407/CloudMe-1.11.2-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/158716/CloudMe-1.11.2-SEH-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/159327/CloudMe-1.11.2-Buffer-Overflow.htmlhttps://blogs.securiteam.com/index.php/archives/3669https://www.exploit-db.com/exploits/44027/https://www.exploit-db.com/exploits/44175/https://www.exploit-db.com/exploits/45197/https://www.exploit-db.com/exploits/46250/https://www.exploit-db.com/exploits/48840