CVE-2024-25004
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.
Las versiones de KiTTY 0.76.1.13 y anteriores son vulnerables a un desbordamiento de búfer en la región stack de la memoria a través del nombre de usuario, que se produce debido a una verificación de los límites y una sanitización de entrada insuficientes (en la línea 2600). Esto permite a un atacante sobrescribir la memoria adyacente, lo que conduce a la ejecución de código arbitrario.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-02-02 CVE Reserved
- 2024-02-08 CVE Published
- 2024-03-14 First Exploit
- 2024-03-15 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (6)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51891 | 2024-03-14 | |
http://seclists.org/fulldisclosure/2024/Feb/13 | 2024-08-01 | |
http://seclists.org/fulldisclosure/2024/Feb/14 | 2024-08-01 | |
https://blog.defcesco.io/CVE-2024-25003-CVE-2024-25004 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
9bis Search vendor "9bis" | Kitty Search vendor "9bis" for product "Kitty" | <= 0.76.1.13 Search vendor "9bis" for product "Kitty" and version " <= 0.76.1.13" | windows |
Affected
|