CVE-2020-37085
HIGHVirtualTablet Server 3.0.2 - Denial of Service via Oversized Thrift Payload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37085. PoCs published by Dolev Farhi.
AI-analyzed exploit summary This PoC exploits a Denial of Service vulnerability in VirtualTablet Server 3.0.2 by sending an overly long string via Thrift protocol, causing the service to crash. The exploit uses the Thrift library to establish a connection and send the malicious payload.
Description
VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive.
Exploits (1)
This PoC exploits a Denial of Service vulnerability in VirtualTablet Server 3.0.2 by sending an overly long string via Thrift protocol, causing the service to crash. The exploit uses the Thrift library to establish a connection and send the malicious payload.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H