CVE-2012-4750
CRITICALEzhometech EzServer 7.0 - Remote Code Execution via AMF Request memcpy Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4750. PoCs published by Lorenzo Cantoni.
AI-analyzed exploit summary This PoC exploits a heap corruption vulnerability in Ezhometech EzServer 7.0 by sending a malformed AMF request with an oversized 'size' field during an RTMP session, leading to a DoS. Remote Code Execution is theorized but not demonstrated.
Description
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service
Exploits (1)
This PoC exploits a heap corruption vulnerability in Ezhometech EzServer 7.0 by sending a malformed AMF request with an oversized 'size' field during an RTMP session, leading to a DoS. Remote Code Execution is theorized but not demonstrated.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H