PT-2017-16403 · Rapid7 · Metasploit+1
Published
2017-03-02
·
Updated
2017-03-21
·
CVE-2017-5228
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Rapid7 Metasploit versions prior to 4.13.0-2017020701
Description
The issue concerns a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. This allows an attacker to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance by using a specially-crafted build of Meterpreter.
Recommendations
For versions prior to 4.13.0-2017020701, update to version 4.13.0-2017020701 or later to resolve the issue. As a temporary workaround, consider restricting access to the Dir.download() function until a patch is applied.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metasploit
Meterpreter