CVE-2021-47764
MEDIUMAbsoluteTelnet 11.24 - Denial of Service via DialUp Connection and License Name Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47764. PoCs published by Yehia Elghaly.
AI-analyzed exploit summary This PoC exploits a Denial of Service (DoS) vulnerability in AbsoluteTelnet 11.24 by overwriting the 'Phone' or 'license name' fields with a large string of 'A' characters, causing the application to crash. The exploit generates a text file with the payload, which is then manually input into the vulnerable fields.
Description
AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating DialUp connection and license name fields. Attackers can generate a 1000-character payload and paste it into specific input fields to trigger application crashes and force unexpected termination.
Exploits (1)
This PoC exploits a Denial of Service (DoS) vulnerability in AbsoluteTelnet 11.24 by overwriting the 'Phone' or 'license name' fields with a large string of 'A' characters, causing the application to crash. The exploit generates a text file with the payload, which is then manually input into the vulnerable fields.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H