CVE-2019-7214
CRITICALSmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution
Title source: metasploitExploitation Summary
EIP tracks 6 public exploits for CVE-2019-7214.
PoCs published by 1F98D, Drew-Alleman, andyfeili, including Metasploit module exploits/windows/http/smartermail_rce.
AI-analyzed exploit summary This exploit targets a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a crafted payload to a .NET remoting endpoint to achieve remote code execution via a PowerShell reverse shell.
Description
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Exploits (6)
This exploit targets a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a crafted payload to a .NET remoting endpoint to achieve remote code execution via a PowerShell reverse shell.
This is a Python-based exploit for CVE-2019-7214, targeting a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a malicious payload to achieve remote code execution via a reverse shell.
This PoC exploits a .NET deserialization vulnerability in SmarterMail before build 6985 to achieve remote code execution. It sends a crafted payload to a .NET remoting endpoint, triggering arbitrary command execution via a PowerShell reverse shell.
This PoC exploits a .NET deserialization vulnerability in SmarterMail before build 6985 to achieve remote code execution. It sends a crafted payload to a .NET remoting endpoint, triggering arbitrary command execution via a PowerShell reverse shell.
This is a functional exploit for CVE-2019-7214, targeting a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a serialized payload to execute a PowerShell reverse shell.
This Metasploit module exploits a .NET deserialization vulnerability (CVE-2019-7214) in SmarterTools SmarterMail versions <= 16.x or builds < 6985. It sends a malicious serialized payload to one of three exposed .NET remoting endpoints on port 17001, achieving unauthenticated remote code execution as SYSTEM.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H