Buffer overflow in CloudMe - CVE-2018-6892
Published: February 15, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability exists due to improper bounds checking by the Sync client application. A remote attacker can connect to the “CloudMe Sync” client application listening on port 8888, send a malicious payload, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2018-6892
Links to Public Exploits and PoC-codes
- Exploit #6294 - Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit) (June 17, 2021)
- Exploit #6317 - CloudMe Sync < 1.11.0 - Buffer Overflow (June 17, 2021)
- Exploit #6038 - CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass) (June 17, 2021)
- Exploit #6039 - CloudMe Sync 1.11.2 - Buffer Overflow + Egghunt (June 17, 2021)
- Exploit #5669 - CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR) (June 17, 2021)
- Exploit #5105 - CVE-Exploits (PoCs for public CVEs I have been working on) (February 1, 2021)
- Exploit #3581 - CVE-2018-6892-Golang (Ported Exploit From Python To Golang) (July 22, 2020)
- Exploit #1601 - CloudMe Sync v1.10.9 (March 18, 2020)