CVE-2014-3913

Eromic AccessNow Server - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-3913. PoCs published by Metasploit, Unknown, juan vazquez, including Metasploit module exploits/windows/http/ericom_access_now_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Ericom AccessNow Server via a malformed HTTP request, leveraging ROP gadgets to achieve remote code execution.

Description

Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/33817

This Metasploit module exploits a stack-based buffer overflow in Ericom AccessNow Server via a malformed HTTP request, leveraging ROP gadgets to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ericom AccessNow Server 2.4.0.2
No auth needed
Prerequisites: Network access to the target server on port 8080
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Unknown, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/ericom_access_now_bof.rb

This Metasploit module exploits a stack-based buffer overflow in Ericom AccessNow Server via a malformed HTTP request, leveraging ROP gadgets to achieve remote code execution. It targets a vulnerability in the handling of user-controlled data with vsprintf.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ericom AccessNow Server 2.4.0.2
No auth needed
Prerequisites: Network access to the target server on port 8080 · Target running Ericom AccessNow Server 2.4.0.2 on Windows XP SP3 or Windows 2003 Server SP2
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67777
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-160
Various Sources x_refsource_confirm
http://www.ericom.com/security-ERM-2014-610.asp
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/33817

Scores

EPSS 0.6086
EPSS Percentile 99.0%

Details

CWE
CWE-119
Status published
Products (1)
ericom/accessnow_server
Published Jun 04, 2014
Tracked Since Feb 18, 2026