CVE-2017-11517

CRITICAL

Geutebrueck Gcore <1.4.2.37 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2017-11517. PoCs published by Maurice Popp, Luca Cappiello, Maurice Popp, including Metasploit module exploits/windows/http/geutebrueck_gcore_x64_rce_bo.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Geutebrueck GCore's GCoreServer.exe (versions 1.3.8.42 and 1.4.2.37) to achieve remote code execution. It uses ROP chains to bypass DEP and execute arbitrary payloads on Windows x64 systems.

Description

Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary code via a long URI in a GET request.

Exploits (2)

exploitdb WORKING POC
by Maurice Popp · rubyremotewindows
https://www.exploit-db.com/exploits/41153

This Metasploit module exploits a stack-based buffer overflow in Geutebrueck GCore's GCoreServer.exe (versions 1.3.8.42 and 1.4.2.37) to achieve remote code execution. It uses ROP chains to bypass DEP and execute arbitrary payloads on Windows x64 systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Geutebrueck GCore (GCoreServer.exe) versions 1.3.8.42 and 1.4.2.37
No auth needed
Prerequisites: Network access to vulnerable GCore server on ports 13003 or 13004 · Target system running Windows x64
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Luca Cappiello, Maurice Popp · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/geutebrueck_gcore_x64_rce_bo.rb

This Metasploit module exploits a stack-based buffer overflow in Geutebrueck GCore's GCoreServer.exe (versions 1.3.8.42 and 1.4.2.37) to achieve remote code execution via a ROP chain and VirtualProtect manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Geutebrueck GCore (GCoreServer.exe) versions 1.3.8.42 and 1.4.2.37
No auth needed
Prerequisites: Network access to TCP port 13003 or 13004 · Vulnerable version of GCoreServer.exe
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41153/

Scores

CVSS v3 9.8
EPSS 0.2908
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
geutebrueck/gcore 1.3.8.42
geutebrueck/gcore 1.4.2.37
Published Jul 21, 2017
Tracked Since Feb 18, 2026