CVE-2020-6514
MEDIUMGoogle Chrome < 84.0.4147.89 - Heap Corruption via Crafted SCTP Stream
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2020-6514. PoCs published by hasan-khalil.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and function pointers.
Description
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Exploits (4)
This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and function pointers.
This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and heap structures.
This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in applications like Duo, JioChat, VK, OK, and Signal. The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution.
This repository contains functional exploit code for CVE-2020-6514, targeting WebRTC implementations in multiple applications (Duo, JioChat, VK, OK, Signal). The exploit leverages memory corruption in the SCTP/SRTP handling to achieve remote code execution (RCE) by manipulating vtables and exploiting predictable PRNG states.
References (27)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N