CVE-2005-2482: Medium severity Metasploit Metasploit Framework vulnerability
The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "Defanged" environment option is checked when processing the Exploit command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2482?
CVE-2005-2482 has a medium severity as it allows attackers to manipulate environment variables in a vulnerable Metasploit Framework.
How do I fix CVE-2005-2482?
To fix CVE-2005-2482, upgrade the Metasploit Framework to version 3.0 or later, which contains the required security patches.
Which versions of Metasploit Framework are affected by CVE-2005-2482?
CVE-2005-2482 affects Metasploit Framework versions 2.0 through 2.4.
Can CVE-2005-2482 lead to arbitrary command execution?
Yes, CVE-2005-2482 can potentially result in arbitrary command execution due to improper handling of environment variables.
What can attackers achieve by exploiting CVE-2005-2482?
By exploiting CVE-2005-2482, an attacker could disrupt the normal operation of Metasploit by modifying critical environment settings.