CVE-2001-0464

Cyberscheduler - Buffer Overflow via Long Timezone Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0464. PoCs published by Enrique A..

AI-analyzed exploit summary This exploit targets a buffer overflow in CrossWind CyberScheduler's 'websyncd' daemon via a maliciously crafted timezone string. It achieves remote code execution as root by overflowing the stack before authentication.

Description

Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Enrique A. · cremotecgi
https://www.exploit-db.com/exploits/20780

This exploit targets a buffer overflow in CrossWind CyberScheduler's 'websyncd' daemon via a maliciously crafted timezone string. It achieves remote code execution as root by overflowing the stack before authentication.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CrossWind CyberScheduler (websyncd daemon)
No auth needed
Prerequisites: Network access to the target server · Vulnerable version of CrossWind CyberScheduler
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=98761402029302&w=2
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2628

Scores

EPSS 0.0674
EPSS Percentile 93.1%

Details

Status published
Products (1)
crosswind/cyberscheduler 2.1
Published Jul 02, 2001
Tracked Since Feb 18, 2026