Showing 2 vulnerabilities on this page for Inbit Messenger

Signals CISA KEV Ransomware Nuclei
Inbit vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable Windows systems.

CWE-121CWE-787Jan 13, 2026
CVSS9.3v4.0EPSS0.706%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE)

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CWE-121CWE-787Jan 13, 2026
CVSS9.3v4.0EPSS1.05%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX