PT-2017-16404 · Rapid7 · Metasploit+1

Publicado

2017-03-02

·

Atualizado

2017-03-21

·

CVE-2017-5229

CVSS v3.1

7.1

Alta

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Rapid7 Metasploit versions prior to 4.13.0-2017020701
Description The issue concerns a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse dump() function. This vulnerability can be exploited by using a specially-crafted build of Meterpreter, allowing an attacker to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Recommendations For versions prior to 4.13.0-2017020701, update to version 4.13.0-2017020701 or later to resolve the issue. As a temporary workaround, consider restricting access to the Clipboard.parse dump() function in the Meterpreter extapi until a patch is applied.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5229

Produtos afetados

Metasploit
Meterpreter