vendor:
SyncBreeze
by:
Owais Mehtab
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SyncBreeze
Affected Version From: 10.0.28
Affected Version To: 10.0.28
Patch Exists: NO
Related CWE:
CPE: a:syncbreeze:syncbreezeent:10.0.28
Platforms Tested: Windows 7
2017
SyncBreeze POST username overflow
This exploit triggers a buffer overflow vulnerability in SyncBreeze, specifically in the POST username field. By sending a large payload of A's, the program crashes. This could potentially be leveraged to execute arbitrary code or gain remote access to the system.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. In the meantime, users should avoid using the affected version and consider using alternative software.