CVE-2017-1182
HIGH EXPLOITEDIBM Tivoli Monitoring Portal <6 - Command Injection
Title source: llmExploitation Summary
CVE-2017-1182 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Morfeen01.
AI-analyzed exploit summary This repository contains a Python script that generates a malicious RTF file exploiting CVE-2017-11882, a vulnerability in Microsoft Office's Equation Editor. The exploit leverages a buffer overflow to achieve remote code execution.
Description
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.
Exploits (1)
This repository contains a Python script that generates a malicious RTF file exploiting CVE-2017-11882, a vulnerability in Microsoft Office's Equation Editor. The exploit leverages a buffer overflow to achieve remote code execution.
References (3)
Scores
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H