vendor:
Sync Breeze Enterprise
by:
Daniel Teixeira
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sync Breeze Enterprise
Affected Version From: 9.5.16
Affected Version To: 9.5.16
Patch Exists: NO
Related CWE: CVE-2017-7310, EDB-41773
CPE: a:sync_breeze:sync_breeze_enterprise
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2017
Sync Breeze Enterprise 9.5.16 – Import Command Buffer Overflow
This module exploits a buffer overflow in Sync Breeze Enterprise 9.5.16 by using the import command option to import a specially crafted xml file.
Mitigation:
DisablePayloadHandler, StackAdjustment, BadChars