Sploitus

CVE-2017-17099

1 known exploit for CVE-2017-17099

There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.

Affected products
Syncbreeze Enterprise
Flexense Syncbreeze
= 10.1.16
CVSS 3.0
7.8 HIGH
EPSS
11.8% (96th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2017-12-03
CVE-2017-17099 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2017-17099

Proof-of-concept code and exploit modules indexed by Sploitus