CVE-2017-7310

HIGH

DiskBoss < 8.9 - Buffer Overflow via Import Command XML Name Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2017-7310. PoCs published by Metasploit, Daniel Teixeira, including Metasploit module exploits/windows/fileformat/dupscout_xml.

AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in Sync Breeze Enterprise 9.5.16 via a maliciously crafted XML file. It leverages SEH overwrites and a JMP ESP technique to achieve remote code execution.

Description

A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.

Exploits (7)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/43875

This Metasploit module exploits a buffer overflow in Sync Breeze Enterprise 9.5.16 via a maliciously crafted XML file. It leverages SEH overwrites and a JMP ESP technique to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 9.5.16
No auth needed
Prerequisites: Victim must open the malicious XML file in Sync Breeze Enterprise
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Daniel Teixeira · pythonlocalwindows
https://www.exploit-db.com/exploits/41772

This exploit targets a buffer overflow vulnerability in DiskBoss Enterprise v7.8.16 via the 'Import Command' feature. It leverages a JMP ESP instruction and a custom shellcode to execute calc.exe, demonstrating arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: DiskBoss Enterprise v7.8.16
No auth needed
Prerequisites: DiskBoss Enterprise v7.8.16 installed on Windows 7 SP1 x86 · Ability to deliver malicious XML file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Daniel Teixeira · pythonlocalwindows
https://www.exploit-db.com/exploits/41771

This exploit targets a buffer overflow vulnerability in DiskSorter Enterprise 9.5.12 via the 'Import Command' feature, leveraging SEH overwrite and shellcode execution to spawn calc.exe. It uses a structured payload with NOPs, JMP ESP, and a custom shellcode.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: DiskSorter Enterprise 9.5.12
No auth needed
Prerequisites: Victim must open the malicious XML file in DiskSorter Enterprise
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Daniel Teixeira · pythonlocalwindows
https://www.exploit-db.com/exploits/41773

This exploit targets a buffer overflow vulnerability in Sync Breeze Enterprise 9.5.16 via the 'Import Command' feature. It leverages SEH overwrites and shellcode execution to spawn calc.exe, demonstrating arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 9.5.16
No auth needed
Prerequisites: Target must be running Sync Breeze Enterprise 9.5.16 on Windows 7 SP1 x86 · Attacker must deliver the malicious XML file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Daniel Teixeira · pythonremotewindows
https://www.exploit-db.com/exploits/44157

This exploit leverages a buffer overflow in Disk Pulse Enterprise v10.4.18 via a malformed XML file to achieve remote code execution. It uses SEH overwrite and shellcode execution to spawn calc.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Disk Pulse Enterprise v10.4.18
No auth needed
Prerequisites: Victim must open the malicious XML file in Disk Pulse Enterprise
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Daniel Teixeira · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/dupscout_xml.rb

This Metasploit module exploits a buffer overflow in Dup Scout Enterprise v10.4.16 via a maliciously crafted XML file. It leverages SEH overwrites and a JMP ESP instruction to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Dup Scout Enterprise v10.4.16
No auth needed
Prerequisites: Victim must open the malicious XML file in Dup Scout Enterprise
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Daniel Teixeira · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/syncbreeze_xml.rb

This Metasploit module exploits a buffer overflow in Sync Breeze Enterprise 9.5.16 via a maliciously crafted XML file. It leverages SEH overwrites and a JMP ESP technique to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sync Breeze Enterprise 9.5.16
No auth needed
Prerequisites: Target must import the malicious XML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41771/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43875/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44157/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41773/
Various Sources x_refsource_confirm
http://www.dupscout.com/news.html
Various Sources x_refsource_confirm
http://www.diskpulse.com/news.html
Various Sources x_refsource_confirm
http://www.diskboss.com/news.html
Various Sources x_refsource_confirm
http://www.vxsearch.com/news.html
Various Sources x_refsource_confirm
http://www.disksorter.com/news.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97237
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41772/
Various Sources x_refsource_confirm
http://www.disksavvy.com/news.html
Various Sources x_refsource_confirm
http://www.syncbreeze.com/news.html

Scores

CVSS v3 7.8
EPSS 0.6681
EPSS Percentile 99.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (3)
flexense/diskboss 7.8.16
flexense/disksorter 9.5.12
flexense/syncbreeze 9.5.16
Published Mar 29, 2017
Tracked Since Feb 18, 2026