CVE-2017-17099
HIGH 7.8EPSS 11.8%
There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.
- CVSS v3.0
- 7.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 11.83% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2017-12-03
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- https://packetstormsecurity.com/files/144586/Sync-Breeze-Enterprise-10.1.16-SEH-Overflow.…
- https://www.exploit-db.com/exploits/42984/