BMC Track-It! 11.3.0.355 exposes .NET Remoting services on TCP port 9010 without requiring authentication. Remote callers can invoke FileStorageService to upload arbitrary files and execute arbitrary code, or invoke ConfigurationService to retrieve configuration information containing application and domain credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module (modules/auxiliary/gather/trackit_sql_domain_creds.rb) targeting BMC/Numara Track-It! versions 9 through 11.X. The module exploits an unauthenticated .NET remoting service exposed by Track-It! to retrieve sensitive configuration data, specifically the Domain Administrator and SQL Server user credentials. The exploit works by crafting a custom .NET remoting packet and sending it to the service (default TCP port 9010). The response is parsed to extract and report credentials, which are then stored in the Metasploit credential database. The module is operational and can be used to obtain real credentials from vulnerable systems. The only network endpoint directly fingerprinted is the .NET remoting service on the target host and port. The code is written in Ruby and is structured as a standard Metasploit module.
This repository contains a single Metasploit module (trackit_file_upload.rb) that exploits an arbitrary file upload vulnerability (CVE-2014-4872) in Numara / BMC Track-It! versions 8 through 11.X on Windows. The exploit targets the FileStorageService .NET remoting service, typically exposed on TCP port 9010 (or 9004 for version 8), which allows unauthenticated file uploads. The module uploads a malicious ASP or ASPX webshell containing a Metasploit payload to the web root of the Track-It! application (default path /TrackItWeb/), then triggers its execution via an HTTP request. Successful exploitation results in remote code execution as NETWORK SERVICE or SYSTEM. The module is weaponized, allowing customizable payloads and is part of the Metasploit framework. The code is well-structured, with options for target ports, sleep timing, and base URI, and includes version detection and fallback mechanisms for payload delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.