CVE-2005-1009

BakBone NetVault <7 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2005-1009. PoCs published by Metasploit, class101, hdm, including Metasploit module exploits/windows/misc/bakbone_netvault_heap.

AI-analyzed exploit summary This exploit targets a heap overflow vulnerability in BakBone NetVault's Process Manager service (CVE-2005-1009). It sends a maliciously crafted packet to trigger the overflow and execute arbitrary payloads on vulnerable Windows systems.

Description

Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16448

This exploit targets a heap overflow vulnerability in BakBone NetVault's Process Manager service (CVE-2005-1009). It sends a maliciously crafted packet to trigger the overflow and execute arbitrary payloads on vulnerable Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BakBone NetVault Process Manager
No auth needed
Prerequisites: Network access to the target service on port 20031 · Vulnerable version of BakBone NetVault
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by class101 · cremotewindows
https://www.exploit-db.com/exploits/906

This exploit targets CVE-2005-1009, a buffer overflow vulnerability in NetVigilance's NVV1.0. It includes shellcode for a reverse shell and is designed to exploit the vulnerability by sending a maliciously crafted packet to the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NetVigilance NVV1.0
No auth needed
Prerequisites: Network access to the target system · Target system running NetVigilance NVV1.0
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by class101 · clocalwindows
https://www.exploit-db.com/exploits/905

This exploit targets a local buffer overflow in BakBone NetVault's configuration file parsing. It modifies the 'configure.cfg' file to include shellcode that adds a local administrator user (class101:class101) upon service restart.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: BakBone NetVault Backup Server (versions up to 2005)
No auth needed
Prerequisites: Local access to the target system · Write permissions to the NetVault configuration file · Ability to restart the NetVault service
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
cremotewindows
https://www.exploit-db.com/exploits/990

This exploit targets a heap overflow vulnerability in BakBone NetVault, sending a crafted packet to overwrite memory and execute shellcode, resulting in a remote command shell on port 101. It includes target-specific offsets for Windows 2000 and XP SP0-1.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BakBone NetVault (demo version)
No auth needed
Prerequisites: Network access to target on port 20031 · Target running vulnerable version of BakBone NetVault
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC NORMAL
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/bakbone_netvault_heap.rb

This Metasploit module exploits a heap overflow in BakBone NetVault's Process Manager service (CVE-2005-1009) by sending a maliciously crafted packet to trigger memory corruption and execute arbitrary payloads. It includes target-specific return addresses and a structured payload delivery mechanism.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BakBone NetVault Process Manager
No auth needed
Prerequisites: Network access to the target service on port 20031 · Vulnerable version of BakBone NetVault
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit, Vendor Advisory x_refsource_misc
http://www.hat-squad.com/en/000165.html
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/394801
Exploit, Vendor Advisory x_refsource_misc
http://www.hat-squad.com/en/000164.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12967
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19932
Vendor Advisory x_refsource_misc
http://www.class101.org/netv-remhbof.pdf
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14814
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013625
Vendor Advisory x_refsource_misc
http://www.class101.org/netv-locsbof.pdf

Scores

EPSS 0.8352
EPSS Percentile 99.3%

Details

Status published
Products (2)
bakbone/netvault 7.0
bakbone/netvault 7.1
Published May 02, 2005
Tracked Since Feb 18, 2026