vendor:
Sync Breeze Enterprise
by:
Daniel Teixeira
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sync Breeze Enterprise
Affected Version From: 9.5.16
Affected Version To: 9.5.16
Patch Exists: YES
Related CWE: N/A
CPE: a:syncbreeze:syncbreeze_enterprise
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 x86
2017
Sync Breeze Enterprise 9.5.16 – ‘Import Command’ Buffer Overflow (SEH)
Sync Breeze Enterprise is prone to a buffer overflow vulnerability when handling specially crafted XML files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This vulnerability affects Sync Breeze Enterprise version 9.5.16.
Mitigation:
Upgrade to the latest version of Sync Breeze Enterprise.