CVE-2004-2687
NUCLEIdistcc 2.x - RCE
Title source: llmDescription
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
Exploits (7)
exploitdb
WORKING POC
VERIFIED
by H D Moore · rubyremotemultiple
https://www.exploit-db.com/exploits/9915
nomisec
WORKING POC
2 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/distccd_rce_CVE-2004-2687
nomisec
WORKING POC
by nulltrace1336 · poc
https://github.com/nulltrace1336/Metasploitable-2-Distcc-Exploit-via-Kali-Linux-CVE-2004-2687
github
NO CODE
by Boon-Rekcah · pythonpoc
https://github.com/Boon-Rekcah/CVE-Exploits/tree/main/CVE-2004-2687(Distccd)
metasploit
WORKING POC
EXCELLENT
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/misc/distcc_exec.rb
Nuclei Templates (1)
Distccd v1 - Remote Code Execution
HIGHVERIFIEDby pussycat0x
References (6)
Scores
EPSS
0.9025
EPSS Percentile
99.6%
Details
CWE
CWE-16
Status
published
Products (2)
apple/xcode
1.5
samba/samba
< 2.18.3
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026