CVE-2009-20005

CRITICAL

InterSystems Caché 2009.1 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-20005. PoCs published by Metasploit, MC, including Metasploit module exploits/windows/http/intersystems_cache.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in InterSystems Cache 2009.1 via a crafted GET request to '/csp/sys/mgr/UtilConfigHome.csp', allowing arbitrary code execution.

Description

A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack buffer, allowing an attacker to overwrite control structures and execute arbitrary code. It is unknown if this vulnerability was patched and an affected version range remains undefined.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16807

This Metasploit module exploits a stack buffer overflow in InterSystems Cache 2009.1 via a crafted GET request to '/csp/sys/mgr/UtilConfigHome.csp', allowing arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: InterSystems Cache 2009.1
No auth needed
Prerequisites: Network access to the target server · Target running InterSystems Cache 2009.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/intersystems_cache.rb

This Metasploit module exploits a stack buffer overflow in InterSystems Cache 2009.1 via a crafted GET request to '/csp/sys/mgr/UtilConfigHome.csp', allowing arbitrary code execution. It uses a SEH-based exploit with a jump-back payload to achieve RCE on Windows 2000 SP4.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: InterSystems Cache 2009.1
No auth needed
Prerequisites: Network access to the target's HTTP service on port 57772 · Target running InterSystems Cache 2009.1 on Windows 2000 SP4
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 9.3
EPSS 0.0127
EPSS Percentile 65.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
InterSystems Corporation/InterSystems Caché < 2009.1
Published Sep 16, 2025
Tracked Since Feb 18, 2026