CVE-2024-23985

HIGH

Ezhometech Ezserver - Denial of Service

Title source: rule

Description

EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.

Exploits (1)

metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/ezserver_http.rb

Scores

CVSS v3 7.5
EPSS 0.3281
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
ezhometech/ezserver 6.4.017
Published Jan 25, 2024
Tracked Since Feb 18, 2026