A buffer overflow vulnerability exists in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16. The vulnerability is triggered by improper handling and sanitization of incoming HTTP GET requests, allowing an attacker to send a specially crafted request that overflows a buffer in the web server component.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/windows/http/dupscts_bof.rb) that exploits a stack-based buffer overflow vulnerability (CVE-2017-13696) in the web interface of Dup Scout Enterprise versions up to 10.0.18 on Windows (x86). The exploit works by sending a specially crafted HTTP GET request with an overlong path to the built-in web server, triggering a buffer overflow and allowing execution of arbitrary code as NT AUTHORITY\SYSTEM. The module supports multiple specific versions of Dup Scout Enterprise, with version-specific offsets and return addresses. The payload is fully customizable via Metasploit and is delivered using an egghunter technique. The module includes automatic target detection and version checking by parsing the web interface's root page. The only network endpoint required is the root path ("/") of the target's web server. The exploit is operational and can be used to gain full SYSTEM-level access on vulnerable targets.
This repository contains a single Metasploit module targeting a buffer overflow vulnerability (CVE-2017-13696) in Disk Pulse Enterprise 9.9.16 for Windows. The exploit leverages a SEH (Structured Exception Handler) buffer overflow via a specially crafted HTTP GET request to the target's web interface. The module allows the attacker to execute arbitrary code as NT AUTHORITY\SYSTEM, providing full control over the target system. The payload is customizable using Metasploit's payload system and is encoded to avoid problematic characters. The module includes a check method to verify if the target is running the vulnerable version by inspecting the HTTP response. The main attack vector is network-based, exploiting the HTTP service (default port 80) exposed by Disk Pulse Enterprise. The code is operational and ready for use within the Metasploit framework.
This repository contains a single Metasploit module targeting a stack buffer overflow vulnerability (CVE-2017-13696) in the web login interface of Dup Scout Enterprise versions 9.9.14 and 10.0.18 on Windows. The exploit works by sending a specially crafted HTTP POST request to the '/login' endpoint, overflowing a stack buffer and executing arbitrary code as NT AUTHORITY\SYSTEM. The module includes automatic version detection by querying the root web page ('/'), and supports both manual and automatic target selection. The payload is customizable using Metasploit's payload system, allowing for reverse shells or other post-exploitation actions. The exploit is operational and has been tested on multiple Windows versions. The only file present is a Ruby script structured as a standard Metasploit exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.