Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-20037. PoCs published by Juan Sacco.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in xwpe v1.5.30a-2.1 by supplying a maliciously crafted argument to the xwpe binary, leading to arbitrary code execution (RCE) via shellcode injection. The PoC includes a clear payload structure (junk, shellcode, NOPs, and EIP overwrite) and has been tested on Kali Linux 2.0.
Description
xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying overly long input strings that exceed buffer boundaries. Attackers can craft malicious command-line arguments with 262 bytes of junk data followed by shellcode to overwrite the instruction pointer and achieve code execution or denial of service.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in xwpe v1.5.30a-2.1 by supplying a maliciously crafted argument to the xwpe binary, leading to arbitrary code execution (RCE) via shellcode injection. The PoC includes a clear payload structure (junk, shellcode, NOPs, and EIP overwrite) and has been tested on Kali Linux 2.0.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H