Stack-based Buffer Overflow in IceWarp Merak Mail Server
CVE-2009-1516

Currently unrated

Key Information:

Vendor

Icewarp

Vendor
CVE Published:
4 May 2009

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2009-1516?

A stack-based buffer overflow exists in the IceWarp Merak Mail Server due to improper handling of input within the IceWarpServer.APIObject ActiveX control in api.dll. This vulnerability can be exploited when an attacker supplies a large value as the second argument to the Base64FileEncode method, potentially allowing the execution of arbitrary code within the context of the affected application. Care should be taken when processing untrusted input, as this may lead to unauthorized access or system compromise.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.