CVE-2017-14980

CRITICAL

Flexense Syncbreeze - Memory Corruption

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 12 public exploits for CVE-2017-14980. PoCs published by LipeOzyy, ahmedmamdouh6, 0xkr3pt0n, including Metasploit module exploits/windows/http/syncbreeze_bof.

AI-analyzed exploit summary This repository contains a functional buffer overflow exploit for CVE-2017-14980 in Sync Breeze Enterprise 10.0.28, leveraging an improperly validated password field in a POST request to execute arbitrary shellcode via EIP overwrite.

Description

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

Exploits (12)

nomisec WORKING POC 2 stars
by LipeOzyy · poc
https://github.com/LipeOzyy/CVE-2017-14980_syncbreeze_10.0.28_bof

This repository contains a functional buffer overflow exploit for CVE-2017-14980 in Sync Breeze Enterprise 10.0.28, leveraging an improperly validated password field in a POST request to execute arbitrary shellcode via EIP overwrite.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise v10.0.28
No auth needed
Prerequisites: Network access to target · C compiler · Adjustment of EIP address and shellcode as needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by ahmedmamdouh6 · poc
https://github.com/ahmedmamdouh6/CVE-2017-14980

This repository contains a functional exploit for CVE-2017-14980, targeting a buffer overflow vulnerability in SyncBreeze version 10.0.28. The exploit uses a reverse shell payload generated via msfvenom to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SyncBreeze 10.0.28
No auth needed
Prerequisites: Network access to the target · Target running SyncBreeze 10.0.28
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WORKING POC
by 0xkr3pt0n · poc
https://github.com/0xkr3pt0n/CVE-2017-14980

This repository contains a functional exploit for CVE-2017-14980, targeting SyncBreeze v10.0.28. The exploit leverages a buffer overflow vulnerability in the login functionality to execute arbitrary shellcode, achieving remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SyncBreeze v10.0.28
No auth needed
Prerequisites: Network access to the target server · SyncBreeze v10.0.28 running on the target
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WORKING POC
by TheMalwareGuardian · poc
https://github.com/TheMalwareGuardian/CVE-2017-14980

This repository contains a functional exploit for CVE-2017-14980, a stack-based buffer overflow in Sync Breeze Enterprise 10.0.28. The exploit includes Python scripts for fuzzing, offset discovery, bad character analysis, and achieving remote code execution via a crafted POST request to the /login endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 10.0.28
No auth needed
Prerequisites: Network access to the target's web interface on port 80
devstral-2 · analyzed Mar 24, 2026 Full analysis →
nomisec WORKING POC
by damariion · poc
https://github.com/damariion/CVE-2017-14980.RCE

This repository contains a functional exploit for CVE-2017-14980, targeting a buffer overflow vulnerability in Sync Breeze Enterprise 10.0.28. The exploit crafts an HTTP POST request with a malformed payload to overwrite the EIP register and execute arbitrary shellcode.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 10.0.28
No auth needed
Prerequisites: Disabled security mitigations (ASLR, CFG, DEP) · Windows 10 (x86, build 16299) · Network access to the target
devstral-2 · analyzed Apr 10, 2026 Full analysis →
nomisec WORKING POC
by damariion · poc
https://github.com/damariion/CVE-2017-14980

This repository contains a functional exploit for CVE-2017-14980, targeting a buffer overflow vulnerability in Sync Breeze Enterprise 10.0.28. The exploit crafts an HTTP POST request with a malformed body to overwrite the EIP register and execute arbitrary shellcode.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 10.0.28
No auth needed
Prerequisites: Disabled security mitigations (ASLR, CFG, DEP) · Windows 10 (x86, build: 16299) · Valid shellcode file
devstral-2 · analyzed Mar 01, 2026 Full analysis →
nomisec WORKING POC
by DaviGSantana · poc
https://github.com/DaviGSantana/CVE-2017-14980

This repository contains a functional proof-of-concept exploit for CVE-2017-14980, a stack-based buffer overflow in Sync Breeze Enterprise 10.0.28. The exploit sends a crafted HTTP POST request to trigger the vulnerability and achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 10.0.28
No auth needed
Prerequisites: Target system with Sync Breeze Enterprise 10.0.28 · Network access to the target · ASLR and DEP disabled on the target
devstral-2 · analyzed Mar 17, 2026 Full analysis →
nomisec WORKING POC
by DaviGSantana · poc
https://github.com/DaviGSantana/Exploit-CVE-2017-14980

This is a functional proof-of-concept exploit for CVE-2017-14980, targeting a stack-based buffer overflow in Sync Breeze Enterprise 10.0.28. The exploit sends a maliciously crafted HTTP POST request to trigger remote code execution via shellcode injection.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 10.0.28
No auth needed
Prerequisites: Network access to the target · Sync Breeze Enterprise 10.0.28 running on Windows with ASLR/DEP disabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by krnlcrow · poc
https://github.com/krnlcrow/CVE-2017-14980

This exploit targets a buffer overflow vulnerability in Sync Breeze Enterprise 10.0.28 via an HTTP POST request, allowing unauthenticated arbitrary code execution. It uses a static JMP ESP address in libspp.dll to redirect execution to shellcode on the stack.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 10.0.28
No auth needed
Prerequisites: Disabled security mitigations (ASLR, CFG, DEP) · Target running Windows 10 x86 build 16299 · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by xn0kkx · poc
https://github.com/xn0kkx/Exploit_Sync_Breeze_v10.0.28_CVE-2017-14980

This repository contains a buffer overflow exploit for Sync Breeze Enterprise v10.0.28, leveraging a JMP ESP address in libspp.dll to execute a reverse shell payload. The exploit is implemented in both C and Python, targeting a vulnerable HTTP endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise v10.0.28
No auth needed
Prerequisites: Network access to the target · Target running Sync Breeze Enterprise v10.0.28
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by TheDarthMole · poc
https://github.com/TheDarthMole/CVE-2017-14980

This repository contains a working exploit for CVE-2017-14980, targeting SyncBreeze v10.0.28. The exploit leverages a buffer overflow vulnerability in the login functionality to achieve remote code execution via a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SyncBreeze v10.0.28
No auth needed
Prerequisites: Network access to the target · Target running SyncBreeze v10.0.28
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by Daniel Teixeira, Andrew Smith, Owais Mehtab, Milton Valencia (wetw0rk) · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/syncbreeze_bof.rb

This Metasploit module exploits a stack-based buffer overflow in Sync Breeze Enterprise via malformed HTTP GET/POST requests. It includes SEH overwrites, egghunter techniques, and payload delivery for versions 9.4.28, 10.0.28, and 10.1.16.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise v9.4.28, v10.0.28, v10.1.16
No auth needed
Prerequisites: Network access to the Sync Breeze web interface · Target running a vulnerable version of Sync Breeze Enterprise
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.2248
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
flexense/syncbreeze 10.0.28
Published Oct 10, 2017
Tracked Since Feb 18, 2026