vendor:
CloudMe
by:
Andy Bowden
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CloudMe
Affected Version From: CloudMe 1.11.2
Affected Version To: CloudMe 1.11.2
Patch Exists: YES
Related CWE: N/A
CPE: a:cloudme:cloudme:1.11.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x86
2020
CloudMe 1.11.2 – Buffer Overflow (PoC)
A buffer overflow vulnerability exists in CloudMe 1.11.2 which can be exploited by sending a specially crafted payload to the service running on port 8888. The vulnerability is caused due to a boundary error when handling user-supplied input, which can result in a stack-based buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of CloudMe 1.11.2