CVE-2004-2687
HIGH 9.3EPSS 88.2%
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 88.20% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-16
- Published
- 2007-09-23
- Updated
- 2024-09-16
Proof-of-concept exploits (20)
- http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html
- http://lists.samba.org/archive/distcc/2004q3/002562.html
- http://lists.samba.org/archive/distcc/2004q3/002550.html
- 0xwh1pl4sh/distccd_rce_CVE-2004-26872★ · 2025-06-05
- 4n0nym0u5dk/distccd_rce_CVE-2004-26872★ · 2025-06-05
- H3xL00m/distccd_rce_CVE-2004-26872★ · 2025-06-05
- N3rdyN3xus/distccd_rce_CVE-2004-26872★ · 2025-06-05
- NyxByt3/distccd_rce_CVE-2004-26872★ · 2025-06-05
- Sp3c73rSh4d0w/distccd_rce_CVE-2004-26872★ · 2025-06-05
- angelpimentell/distcc_cve_2004-2687_exploit1★ · 2022-03-15
- c0d3cr4f73r/distccd_rce_CVE-2004-26872★ · 2025-06-05
- crypticdante/distccd_rce_CVE-2004-26872★ · 2025-06-05
- gregtampa/HBCTF-Battlegrounds1★ · 2017-05-08
- h3x0v3rl0rd/distccd_rce_CVE-2004-26872★ · 2025-06-05
- h3xcr4ck3r/distccd_rce_CVE-2004-26872★ · 2025-06-05
- k4miyo/CVE-2004-26871★ · 2021-08-28
- k4u5h41/distccd_rce_CVE-2004-26872★ · 2025-06-05
- n3ov4n1sh/distccd_rce_CVE-2004-26872★ · 2025-06-05
- n3rdh4x0r/distccd_rce_CVE-2004-26872★ · 2025-06-05
- nulltrace1336/Metasploitable-2-Distcc-Exploit-via-Kali-Linux-CVE-2004-2687