PT-2017-16406 · Rapid7 · Metasploit+1

Published

2017-03-02

·

Updated

2017-03-21

·

CVE-2017-5231

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Rapid7 Metasploit versions prior to 4.13.0-2017020701
Description The issue concerns a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd download() function. This vulnerability can be exploited by using a specially-crafted build of Meterpreter, allowing an attacker to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Recommendations For versions prior to 4.13.0-2017020701, update to version 4.13.0-2017020701 or later to resolve the issue. As a temporary workaround, consider restricting access to the cmd download() function in the Meterpreter stdapi CommandDispatcher to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5231

Affected Products

Metasploit
Meterpreter