CVE-2016-9176

CRITICAL

Micro Focus Rumba <9.4 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-9176. PoCs published by Umit Aksu.

AI-analyzed exploit summary This exploit demonstrates a local stack overflow in Micro Focus Rumba 9.4 by overwriting EIP and SEH/NSEH via memory spraying. The PoC uses the `send.exe` and `receive.exe` utilities to trigger the vulnerability.

Description

Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or attackers able to inject arguments to these binaries to execute code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Umit Aksu · textdoswindows
https://www.exploit-db.com/exploits/40648

This exploit demonstrates a local stack overflow in Micro Focus Rumba 9.4 by overwriting EIP and SEH/NSEH via memory spraying. The PoC uses the `send.exe` and `receive.exe` utilities to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Micro Focus Rumba 9.4
No auth needed
Prerequisites: Local access to the system with Rumba 9.4 installed · Ability to execute `send.exe` or `receive.exe`
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94236
Exploit, Third Party Advisory x_refsource_misc
https://www.exploit-db.com/exploits/40648/

Scores

CVSS v3 9.8
EPSS 0.0191
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
Micro Focus/Micro Focus Rumba 9.4 Micro Focus Rumba 9.4
microfocus/rumba < 9.4.0
Published Nov 04, 2016
Tracked Since Feb 18, 2026