CVE-2019-25364
CRITICALMailCarrier 2.51 - Remote Code Execution via POP3 USER Command Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25364. PoCs published by Lance Biggerstaff.
AI-analyzed exploit summary This exploit demonstrates a remote buffer overflow in Win10 MailCarrier 2.51 via the POP3 USER command. It uses a crafted payload with a reverse TCP shell to achieve remote code execution, requiring adjustments for different Windows 10 versions due to varying offsets.
Description
MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access.
Exploits (1)
This exploit demonstrates a remote buffer overflow in Win10 MailCarrier 2.51 via the POP3 USER command. It uses a crafted payload with a reverse TCP shell to achieve remote code execution, requiring adjustments for different Windows 10 versions due to varying offsets.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H