vendor:
Mdaemon
by:
muts
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: Mdaemon
Affected Version From: 7.2.2000
Affected Version To: 9.0.5
Patch Exists: YES
Related CWE: N/A
CPE: a:alt-n_technologies:mdaemon
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000
2005
MDaemon Pre Authentication (USER) Heap Overflow
Mdaemon is vulnerable to a heap overflow vulnerability when a maliciously crafted USER command is sent to the server. This exploit overwrites UnhandledExceptionFilter, and jumps to an egghunter shellcode which then scans the memory, and executes a bindshell on port 4444. The exploit is partially working on unpatched Win2k boxes, but may result in a crash or Mdaemon process shooting up to 100%.
Mitigation:
Apply the latest security patches to the Mdaemon server.