CVE-2018-25222
HIGHSC 7.16 - Stack Buffer Overflow Local Code Execution
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25222. PoCs published by Juan Sacco.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in SC v7.16, allowing arbitrary code execution via a crafted buffer with shellcode and a manipulated EIP address. The PoC uses a NOP sled and shellcode to spawn a shell, confirming the vulnerability.
Description
SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in SC v7.16, allowing arbitrary code execution via a crafted buffer with shellcode and a manipulated EIP address. The PoC uses a NOP sled and shellcode to spawn a shell, confirming the vulnerability.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H