CVE-2018-1041
HIGHjboss-remoting - Denial of Service via RemoteMessageChannel Infinite Loop
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1041. PoCs published by Frank Spierings.
AI-analyzed exploit summary This exploit sends four null bytes to trigger a denial of service in JBoss Remoting, causing CPU spikes on the target system. It leverages a vulnerability in JBoss EAP versions prior to 6.14.19.
Description
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.
Exploits (1)
This exploit sends four null bytes to trigger a denial of service in JBoss Remoting, causing CPU spikes on the target system. It leverages a vulnerability in JBoss EAP versions prior to 6.14.19.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H