CVE-2014-8322
CRITICALaircrack-ng < 1.2 RC 1 - Remote Code Execution via Crafted Length Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8322. PoCs published by Nick Sampanis.
AI-analyzed exploit summary This exploit targets a stack overflow in Aireplay-ng 1.2 beta3 via the '--test' option, leveraging a crafted TCP packet to achieve remote code execution. It constructs a malicious payload with ROP gadgets to execute arbitrary commands, defaulting to a reverse shell.
Description
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
Exploits (1)
This exploit targets a stack overflow in Aireplay-ng 1.2 beta3 via the '--test' option, leveraging a crafted TCP packet to achieve remote code execution. It constructs a malicious payload with ROP gadgets to execute arbitrary commands, defaulting to a reverse shell.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H