[0day-rubbish] CaptureBites MetaServer Anonymous WCF SOAP workflow leading to RunPrograms code execution (9.8)
Unauthenticated attackers can trigger CaptureBites MetaServer RunPrograms execution as SYSTEM through an anonymous WCF SOAP workflow.
0day Rubbish Research Team disclosed an unauthenticated code-execution flaw in CaptureBites MetaServer. An anonymous WCF SOAP workflow can invoke RunPrograms (CWE-306), producing arbitrary command execution as NT AUTHORITY\SYSTEM on the MetaServer host. The stated CVSS is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The mailing-list post points to a full technical analysis and reproducible proof-of-concept but names no CVE and does not claim in-the-wild use.
- CaptureBites MetaServer; no build version given in the post.
- Anonymous WCF SOAP workflow reaches the RunPrograms action.
- Unauthenticated command execution as NT AUTHORITY\SYSTEM; CVSS 9.8.
- Public PoC claimed; no CVE or observed exploitation stated.
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in CaptureBites MetaServer. Type: Anonymous WCF SOAP workflow leading to RunPrograms code execution (CWE-306) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: arbitrary command execution as NT AUTHORITY\SYSTEM on the MetaServer host Authentication: unauthenticated Full technical analysis and a reproducible proof-of-concept:...
This source does not provide full text. Read it at seclists.org.