CVE-2008-2158

EMC AlphaStor 3.1 SP1 - Remote Code Execution via Crafted TCP Packets

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-2158. PoCs published by Metasploit, including Metasploit module exploits/windows/emc/alphastor_agent.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in EMC AlphaStor 3.1 via a crafted message sent to port 41025. It leverages a known return address in dblib9.dll to achieve remote code execution.

Description

Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote attackers to execute arbitrary code via crafted TCP packets to port 41025.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16391

This Metasploit module exploits a stack buffer overflow in EMC AlphaStor 3.1 via a crafted message sent to port 41025. It leverages a known return address in dblib9.dll to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EMC AlphaStor 3.1
No auth needed
Prerequisites: Network access to port 41025 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/emc/alphastor_agent.rb

This Metasploit module exploits a stack buffer overflow in EMC AlphaStor 3.1 by sending a crafted message to port 41025, allowing arbitrary code execution. The exploit constructs a malicious payload with NOP sleds, a return address, and shellcode to achieve RCE.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EMC AlphaStor 3.1
No auth needed
Prerequisites: Network access to port 41025 on the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=702
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1020115
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30410
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29399
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1670
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42669

Scores

EPSS 0.5840
EPSS Percentile 99.0%

Details

CWE
CWE-119
Status published
Products (1)
emc_corporation/alphastor 3.1_sp1
Published May 29, 2008
Tracked Since Feb 18, 2026