Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-6481.
PoCs published by Daniel Teixeira, including Metasploit module exploits/windows/misc/disk_savvy_adm.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Disk Savvy Enterprise v10.4.18, leveraging an SEH overwrite to execute a bind shell payload. The payload is crafted to bypass bad characters and uses a known DLL address for reliable exploitation.
Description
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.
Exploits (2)
This exploit targets a buffer overflow vulnerability in Disk Savvy Enterprise v10.4.18, leveraging an SEH overwrite to execute a bind shell payload. The payload is crafted to bypass bad characters and uses a known DLL address for reliable exploitation.
This Metasploit module exploits a stack-based buffer overflow in Disk Savvy Enterprise v10.4.18 by sending a maliciously crafted packet to the built-in server on port 9124. The exploit leverages SEH overwrites and a JMP ESP technique to achieve remote code execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H