CVE-2018-6537
CRITICALFlexense SyncBreeze Enterprise 10.4.18 - Remote Code Execution via Control Protocol Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2018-6537. PoCs published by Daniel Teixeira, damariion, krnlcrow.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Sync Breeze Enterprise v10.4.18, leveraging SEH overwrite to achieve remote code execution via a bind shell. The payload includes shellcode generated by msfvenom and a structured header to trigger the overflow.
Description
A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9121.
Exploits (4)
This exploit targets a buffer overflow vulnerability in Sync Breeze Enterprise v10.4.18, leveraging SEH overwrite to achieve remote code execution via a bind shell. The payload includes shellcode generated by msfvenom and a structured header to trigger the overflow.
This repository contains a functional exploit for CVE-2018-6537, targeting Sync Breeze version 10.4.18 on Windows 10 (x86). The exploit leverages a SEH overflow via a TCP connection to achieve remote code execution, assuming security mitigations like ASLR and DEP are disabled.
This repository contains a functional exploit for CVE-2018-6537, targeting Sync Breeze 10.4.18 on Windows 10 (x86). The exploit leverages a SEH overflow via a crafted TCP payload to achieve remote code execution, assuming security mitigations like ASLR, CFG, and DEP are disabled.
This exploit targets a SEH overflow vulnerability in Sync Breeze 10.4.18 on Windows 10 (x86) via a TCP connection, allowing unauthenticated remote code execution. It uses a structured buffer with NOP sleds, SEH/NSEH overwrites, and shellcode execution.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H