vendor:
Sync Breeze Enterprise
by:
Nipun Jaswal & Anurag Srivastava
9.8
CVSS
CRITICAL
SEH Buffer Overflow
119
CWE
Product Name: Sync Breeze Enterprise
Affected Version From: v9.9.16
Affected Version To: v9.9.16
Patch Exists: NO
Related CWE:
CPE: sync_breeze_enterprise:9.9.16
Platforms Tested: Windows 7 SP1 x64
2017
Sync Breeze Enterprise v9.9.16 Remote SEH Buffer Overflow
This exploit triggers a remote SEH buffer overflow in Sync Breeze Enterprise v9.9.16. By sending a specially crafted request to the web server, an attacker can execute arbitrary code on the target system.
Mitigation:
To mitigate this vulnerability, users should update to a patched version of Sync Breeze Enterprise that addresses this issue. It is also recommended to restrict access to the web server to trusted networks only.