PoC Index

CVE-2016-6598

HIGH 10.0EPSS 19.2%

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
19.24% chance of exploitation in the next 30 days, 97th percentile
Published
2018-01-30
Updated
2024-08-06

Proof-of-concept exploits (3)

ExploitDB entries (1)

References

Related