Beveiligingsadvies

CVE-2017-5229

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-03-02 20:00:00
Laatst bijgewerkt 2024-08-05 14:55:35
Toegewezen door rapid7
CVSS-score geen score
Status PUBLISHED

Beschrijving

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.