Exploitation Summary
EIP tracks 2 public exploits for CVE-2025-27480. PoCs published by mrk336.
AI-analyzed exploit summary This repository contains a PowerShell-based proof-of-concept exploit for CVE-2025-27480, a buffer overflow vulnerability in OpenSSH 8.9p1. The exploit crafts a malicious SSH_USERAUTH packet with an oversized 'user' field to trigger arbitrary code execution, demonstrating a reverse shell payload.
Description
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Exploits (2)
This repository contains a PowerShell-based proof-of-concept exploit for CVE-2025-27480, a buffer overflow vulnerability in OpenSSH 8.9p1. The exploit crafts a malicious SSH_USERAUTH packet with an oversized 'user' field to trigger arbitrary code execution, demonstrating a reverse shell payload.
This repository contains a working proof-of-concept exploit for CVE-2025-27480, a stack buffer overflow vulnerability in a fictional BarServer service. The exploit sends a crafted HTTP GET request to overflow the stack and execute a reverse shell payload.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H