Описание
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitPatchThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.19.0 (исключая)
cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.66075
Средний
7 High
CVSS3
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-77
CWE-77
Связанные уязвимости
github
больше 3 лет назад
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
EPSS
Процентиль: 98%
0.66075
Средний
7 High
CVSS3
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-77
CWE-77