CVE-2017-6506
CRITICALAzure Data Expert Ultimate 2.2.16 - Remote Code Execution via SMTP 220 String Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6506. PoCs published by Peter Baris.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Azure Data Expert Ultimate 2.2.16 via a maliciously crafted SMTP response. It uses a reverse Meterpreter shell payload split into two parts to bypass bad characters and achieve remote code execution.
Description
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Azure Data Expert Ultimate 2.2.16 via a maliciously crafted SMTP response. It uses a reverse Meterpreter shell payload split into two parts to bypass bad characters and achieve remote code execution.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H