vendor:
Mailenable Enterprise
by:
mati@see-security.com
7.5
CVSS
HIGH
Buffer Overflow
Unknown
CWE
Product Name: Mailenable Enterprise
Affected Version From: Mailenable Enterprise 1.1
Affected Version To: Mailenable Enterprise 1.1 without ME-10009.EXE patch
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Remote Mailenable Enterprise 1.1 EXAMINE buffer Overflow
This vulnerability affects Mailenable Enterprise 1.1 without the ME-10009.EXE patch. SEH gets overwritten at 965 (968 in VMWare) bytes in the EXAMINE command. Filtering of 0x00 0x0a 0x0d 0x20 0x22. No space for shellcode, so 1st stage shellcode is used to jump back 512 bytes into the bindshell (2nd stage) shellcode.
Mitigation:
Apply ME-10009.EXE patch