Directory Traversal Vulnerability in Rapid7 Metasploit
CVE-2017-5229

7.1HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
2 March 2017

What is CVE-2017-5229?

The directory traversal vulnerability in Rapid7 Metasploit allows attackers using a specially-crafted build of Meterpreter to exploit the Clipboard.parse_dump() function. This exploitation can lead to unauthorized writing in arbitrary directories on the Metasploit console, gaining access with the privileges of the Metasploit instance. Users of versions prior to 4.13.0-2017020701 should take immediate action to mitigate potential risks.

Affected Version(s)

Metasploit All versions prior to version 4.13.0-2017020701

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.