CVE-2023-54330
CRITICALInbit Messenger 4.6.0-4.9.0 - Unauthenticated Remote Code Execution via SEH Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-54330. PoCs published by a-rey.
AI-analyzed exploit summary This exploit targets an unauthenticated remote SEH overflow vulnerability in Inbit Messenger versions 4.6.0 to 4.9.0. It uses a structured payload with a NOP sled, SEH overwrite, and encoded shellcode to achieve remote code execution.
Description
Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable Windows systems.
Exploits (1)
This exploit targets an unauthenticated remote SEH overflow vulnerability in Inbit Messenger versions 4.6.0 to 4.9.0. It uses a structured payload with a NOP sled, SEH overwrite, and encoded shellcode to achieve remote code execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H