vendor:
Bifrost
by:
Mohamed Clay
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Bifrost
Affected Version From: 1.2d
Affected Version To: 1.2d
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Bifrost 1.2d Exploit
This is an exploit for Bifrost 1.2d that allows remote code execution. The exploit utilizes the RC4 encryption algorithm to encrypt the payload and then sends it to the vulnerable host. The payload contains a shellcode that executes the 'calc.exe' process.
Mitigation:
Upgrade to a patched version of Bifrost to prevent this exploit.