CVE-2020-37001: Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37001?
CVE-2020-37001 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2020-37001?
To mitigate CVE-2020-37001, update to the latest version of Frigate Professional that addresses this buffer overflow vulnerability.
What impact does CVE-2020-37001 have on systems?
CVE-2020-37001 allows attackers to execute arbitrary code locally, potentially compromising system integrity and security.
Is CVE-2020-37001 easily exploitable?
Yes, CVE-2020-37001 can be easily exploited by crafting a malicious pack file that triggers the buffer overflow.
What software is affected by CVE-2020-37001?
CVE-2020-37001 affects Frigate Professional version 3.36.0.9 specifically.