CVE-2020-7385
Metasploit Framework 'drb_remote_codeexec' code execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework typically runs with elevated privileges, this can lead to a system compromise on the Metasploit workstation. Note that an attacker would have to lie in wait and entice the Metasploit user to run the affected module against a malicious endpoint in a "hack-back" type of attack. Metasploit is only vulnerable when the drb_remote_codeexec module is running. In most cases, this cannot happen automatically.
Al lanzar el exploit drb_remote_codeexec, un usuario de Metasploit Framework expondrá inadvertidamente un Metasploit al mismo problema de deserialización que explota ese módulo, debido a la dependencia de las funciones vulnerables de la clase Distributed Ruby. Dado que Metasploit Framework generalmente se ejecuta con privilegios elevados, esto puede conllevar a un compromiso del sistema en la estación de trabajo Metasploit. Tome en cuenta a un atacante tendría que esperar y convencer al usuario de Metasploit para que ejecute el módulo afectado contra un endpoint malicioso en un tipo de ataque de "hack-back". Metasploit solo es vulnerable cuando se está ejecutando el módulo drb_remote_codeexec. En la mayoría de los casos, esto no puede suceder automáticamente
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-21 CVE Reserved
- 2021-04-23 CVE Published
- 2024-01-07 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/rapid7/metasploit-framework/pull/14300 | 2024-09-17 |
URL | Date | SRC |
---|---|---|
https://github.com/rapid7/metasploit-framework/pull/14335 | 2021-05-14 |
URL | Date | SRC |
---|---|---|
https://help.rapid7.com/metasploit/release-notes/archive/2020/10 | 2021-05-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rapid7 Search vendor "Rapid7" | Metasploit Search vendor "Rapid7" for product "Metasploit" | < 4.19.0 Search vendor "Rapid7" for product "Metasploit" and version " < 4.19.0" | - |
Affected
|