CVE-2017-4914
CRITICALVMware vSphere Data Protection 5.5.x-6.1.x - Remote Code Execution via Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-4914. PoCs published by Kelly Correll.
AI-analyzed exploit summary This exploit targets a deserialization vulnerability in JBoss Application Server, allowing remote command execution via crafted serialized data. The payload is sent over a socket connection, with optional SSL support.
Description
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
Exploits (1)
This exploit targets a deserialization vulnerability in JBoss Application Server, allowing remote command execution via crafted serialized data. The payload is sent over a socket connection, with optional SSL support.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H