ZeroHour

CVE-2017-5231

CVSS 3.0
7.1 high
EPSS
1%p67
Published
()
Modified
Description

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

Vendors
rapid7
Products
metasploit
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.