CVE-2022-23253
MEDIUMWindows - Denial of Service in Point-to-Point Tunneling Protocol
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-23253. PoCs published by nettitude.
AI-analyzed exploit summary This PoC exploits CVE-2022-23253, a vulnerability in PPTP VPN servers, by sending maliciously crafted control messages to trigger a buffer overflow. The code includes structured packet crafting for PPTP control messages, enabling potential remote code execution or denial of service.
Description
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Exploits (1)
This PoC exploits CVE-2022-23253, a vulnerability in PPTP VPN servers, by sending maliciously crafted control messages to trigger a buffer overflow. The code includes structured packet crafting for PPTP control messages, enabling potential remote code execution or denial of service.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H