CVE-2008-5405

Cain & Abel <4.9.24 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an RDP file containing a long string.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalaix
https://www.exploit-db.com/exploits/16659
exploitdb WORKING POC VERIFIED
by Encrypt3d.M!nd · pythonlocalwindows
https://www.exploit-db.com/exploits/7329
exploitdb WORKING POC VERIFIED
by SkD · perllocalwindows
https://www.exploit-db.com/exploits/7309
exploitdb WORKING POC VERIFIED
by Encrypt3d.M!nd · pythondoswindows
https://www.exploit-db.com/exploits/7297
metasploit WORKING POC GOOD
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/cain_abel_4918_rdp.rb

Scores

EPSS 0.8298
EPSS Percentile 99.3%

Details

CWE
CWE-119
Status published
Products (2)
oxid/cain_and_abel 4.9.23
oxid/cain_and_abel 4.9.24
Published Dec 10, 2008
Tracked Since Feb 18, 2026