CVE-2013-0946

EMC AlphaStor 4.0 <build 910 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-0946. PoCs published by James Fitts.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in EMC AlphaStor Library Manager via opcode 0x4f, leveraging a ROP chain to achieve remote code execution. The exploit targets Windows Server 2003 SP2 EN by sending a maliciously crafted packet to port 3500.

Description

Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via crafted commands.

Exploits (1)

exploitdb WORKING POC
by James Fitts · rubyremotewindows
https://www.exploit-db.com/exploits/42719

This Metasploit module exploits a stack-based buffer overflow in EMC AlphaStor Library Manager via opcode 0x4f, leveraging a ROP chain to achieve remote code execution. The exploit targets Windows Server 2003 SP2 EN by sending a maliciously crafted packet to port 3500.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: EMC AlphaStor Library Manager < 4.0 build 910
No auth needed
Prerequisites: Network access to port 3500 · Target running vulnerable EMC AlphaStor Library Manager
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-05/0035.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/59794
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42719/

Scores

EPSS 0.2855
EPSS Percentile 97.9%

Details

CWE
CWE-119
Status published
Products (1)
emc/alphastor 4.0
Published May 10, 2013
Tracked Since Feb 18, 2026