CVE-2017-17099
HIGHFlexense SyncBreeze Enterprise <10.1.16 - Buffer Overflow
Title source: llmDescription
There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.
Exploits (2)
Scores
CVSS v3
7.8
EPSS
0.0908
EPSS Percentile
92.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (1)
flexense/syncbreeze
10.1.16
Published
Dec 03, 2017
Tracked Since
Feb 18, 2026