A buffer overflow vulnerability exists in Sync Breeze Enterprise version 10.0.28, where remote attackers can trigger a buffer overflow by supplying an excessively long username parameter to the /login endpoint. The vulnerable code fails to properly validate or limit the length of the username input, leading to memory corruption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
13 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Small exploit repository for CVE-2017-14980 targeting Flexense Sync Breeze Enterprise 10.0.28 on Windows. The repository contains a README documenting the exploit-development workflow, a bad-character reference file, and a single Python 2 exploit script. The exploit is a network/web attack that sends a crafted HTTP POST request to the /login endpoint on TCP/80. The password parameter carries the overflow buffer: 520 bytes of padding, a hardcoded little-endian return address for JMP ESP (0x10090c83), a short NOP sled, and attacker shellcode. The included shellcode body is intentionally removed, but the README states the intended payload is msfvenom-generated windows/shell_reverse_tcp shellcode, so the exploit is capable of arbitrary code execution and typically reverse shell access once a valid payload is inserted. The repository appears to be a genuine educational PoC rather than a detection script or fake exploit. Structure is minimal: README.md explains fuzzing, crash validation, EIP control, bad character analysis, gadget discovery with Mona, and final exploit assembly; scripts/badchars.txt lists all byte values for bad-char testing; scripts/exploit.py is the operational exploit skeleton.
This repository is a minimal exploit PoC for CVE-2017-14980 targeting Flexense SyncBreeze 10.0.28. It contains only two files: a short README naming the vulnerability and a single Python script implementing the exploit. The script is the clear entry point and performs all exploitation logic directly with Python's socket library rather than using any external framework. The exploit opens a raw TCP connection to a configurable target IP and port (default 192.168.138.129:80), then crafts an HTTP POST request to /login. The malicious input is placed in the username form field. The buffer layout shows classic stack overflow exploitation: 780 bytes of padding, an overwritten return address pointing to a JMP ESP instruction in libspp.dll (hardcoded as 0x10090c83 in little-endian form), a short NOP sled, and embedded Windows reverse shell shellcode, followed by additional padding. Comments indicate the shellcode was generated with msfvenom using a windows/shell_reverse_tcp payload configured for callback to 192.168.138.128:443. Operationally, this is a real exploit rather than a detector: it attempts remote code execution against the SyncBreeze web interface and, if successful, yields a reverse shell. It is not highly flexible because target details, return address, and payload are hardcoded, but it is beyond a bare crash PoC because it includes a working payload and delivery mechanism. The repository has no auxiliary tooling, no setup automation, and no evasion or reliability features; its purpose is straightforward exploitation of the vulnerable login handler over HTTP.
This repository is a minimal standalone exploit for CVE-2017-14980 targeting Flexense SyncBreeze v10.0.28. It contains only a short README and a single Python script, exploit.py, which is the clear entry point. The script uses Python's socket library to open a raw TCP connection to a hardcoded target at 192.168.64.220:80 and manually constructs an HTTP POST request to the /login endpoint. The exploit abuses a stack-based buffer overflow in the login processing by placing an oversized value in the username form field while keeping password=admin. The buffer layout is classic saved-EIP overwrite style: 780 'A' bytes, followed by a hardcoded little-endian return address 0x10090c83 identified as a JMP ESP in libsapp.dll, then a 32-byte NOP sled, then embedded msfvenom shellcode. The shellcode is a Windows reverse TCP shell payload configured to connect back to 192.168.64.4:443. Operationally, successful exploitation yields remote code execution on the Windows host running SyncBreeze and returns a reverse shell to the attacker. The exploit is not a scanner or detector; it is an active weaponized PoC with a fixed payload and target assumptions. It is not part of a larger exploit framework. The code is simple and purpose-built, with no argument parsing, no reliability checks, and no automatic listener setup, so it is best classified as OPERATIONAL rather than fully weaponized.
This repository is a small standalone Python proof-of-concept/operational exploit for CVE-2017-14980 affecting Flexense Sync Breeze Enterprise 10.0.28. The repository contains only two files: exploit.py and readme.md. The Python script is the sole code artifact and serves as the entry point. It accepts three required command-line arguments: --host, --port, and --file. The script reads raw shellcode bytes from the supplied file, wraps them in a crafted application/x-www-form-urlencoded POST body, and sends the request directly over a TCP socket to the target service. The exploit logic is straightforward: encap() builds the overflow buffer as username= followed by 780 padding bytes, a 4-byte hardcoded return address (\x83\x0c\x09\x10, i.e. 0x10090c83 in little endian), 4 more padding bytes, a 16-byte NOP sled, the attacker-provided shellcode, and finally &password=?. inject() then constructs an HTTP request targeting POST /login with the proper Host, Content-Type, and Content-Length headers and transmits it to the specified host and port. The README explains that 0x10090c83 corresponds to a jmp esp instruction in libspp.dll and that the overwrite occurs at byte offset 788, enabling execution of the shellcode placed on the stack. Capabilities: the exploit performs unauthenticated remote code execution by exploiting a stack-based buffer overflow in the Sync Breeze login handler. It does not generate shellcode itself, perform target discovery, or validate success; instead it acts as a delivery mechanism for arbitrary raw shellcode produced elsewhere (for example, msfvenom as noted in the README). Because the payload is operator-supplied but the exploit is otherwise fixed and simple, the maturity is best characterized as OPERATIONAL rather than a framework-integrated or highly weaponized exploit. Fingerprintable targets and artifacts are limited but clear: the vulnerable endpoint is /login over HTTP, reached via a raw TCP connection to an operator-specified host and port; the exploit references libspp.dll as the source of the jmp esp gadget; and it requires a local shellcode file as input. Overall, the repository's purpose is to demonstrate and operationalize a classic Windows stack overflow against Sync Breeze Enterprise using a manually constructed HTTP request and a hardcoded control-flow redirection gadget.
This repository is a structured exploit-development walkthrough for CVE-2017-14980, a stack-based buffer overflow in Flexense Sync Breeze Enterprise 10.0.28. It is not a framework module; it is a standalone educational repository containing seven Python proof-of-concept/exploit stages plus Markdown documentation. The exploit path is entirely network-based: each script opens a raw TCP socket to the target web interface on port 80 and sends an HTTP POST request to /login with a crafted application/x-www-form-urlencoded body, abusing the password parameter. Repository structure is simple and instructional. Top-level README.md explains the vulnerability, affected product, and why the case is useful for teaching. The Vulnerability/README.md file provides the step-by-step methodology: fuzzing, cyclic pattern offset discovery, EIP control, bad character analysis, gadget selection, shellcode generation, and final RCE. The 01 Environment and 02 Resources folders only contain references to related training material. The actual exploit code lives under Vulnerability/Exploit/ and is split into sequential stages: - 01Python3Connection.py: baseline connectivity and normal POST to /login. - 02Python3Fuzzing.py: increases password length until the service crashes. - 03Python3EIPOffsetDiscovery.py: sends a cyclic pattern to identify the exact EIP offset. - 04Python3ControlEIP.py: confirms control of EIP with 520 bytes + BBBB. - 05Python3FindBadChars.py: sends a bytearray after EIP to identify disallowed bytes. - 06Python3JMPESP.py: overwrites EIP with a fixed JMP ESP gadget from libspp.dll and uses NOP/INT3 markers to verify execution flow. - 07Python3Shellcode.py: final exploit buffer with padding, gadget overwrite, NOP sled, and embedded x86 shellcode. Main exploit capabilities: remote unauthenticated crash, reliable EIP overwrite, bad-character testing in an HTTP form context, redirection of execution through a non-ASLR module, and final arbitrary code execution in the target process. The documentation explicitly notes HTTP-specific bad characters caused by URL decoding: \x00, \x0a, \x0d, \x25 (%), \x26 (&), \x2b (+), and \x3d (=). The exploit assumes a stable gadget at 0x10090c83 in libspp.dll. Overall, this is a real exploit repository with operational PoC code and a final RCE stage, intended primarily for exploit-development training rather than stealth or automation.
This repository is a small standalone exploit PoC for CVE-2017-14980 affecting Flexense Sync Breeze Enterprise 10.0.28. It contains only two files: a README describing the vulnerability and test conditions, and a single C source file implementing the exploit. The code is not part of a larger framework. The exploit is a remote network-based stack buffer overflow against the product's web authentication interface. In exploit.c, the program creates a TCP socket, connects to a hardcoded target at 192.168.0.25 on port 80, and sends a crafted HTTP POST request to /login. The POST body uses application/x-www-form-urlencoded data with username=admin and a maliciously oversized password value. The overflow buffer is built as follows: 520 'A' bytes, a 4-byte hardcoded EIP overwrite (\x83\x0c\x09\x10), a 20-byte NOP sled, and embedded x86 shellcode. This indicates a classic saved return address overwrite followed by redirection into attacker-controlled shellcode. The exploit then sends the request and reads a response, but does not implement any interactive session handling or payload customization. Repository structure is minimal and purpose-built: README.md provides context, CVE, affected version, and environmental assumptions; exploit.c contains all exploit logic including socket creation, payload construction, and HTTP request generation. The PoC appears operational but environment-specific due to the fixed IP, fixed return address, and reliance on disabled exploit mitigations. It is a real exploit PoC rather than a scanner or detection script.
Repository contains a single Python exploit (exploit.py) and documentation (readme.md) for CVE-2017-14980 affecting Sync Breeze Enterprise. The exploit is an unauthenticated remote buffer overflow delivered in the body of an HTTP POST to /login using application/x-www-form-urlencoded. It constructs a payload of the form "username=<overflow>&password=?" where the overflow is 780 bytes of padding followed by an EIP overwrite with the hardcoded address 0x10090c83 (documented as a jmp esp gadget in libspp.dll), then a small NOP sled and attacker-supplied shellcode read from a local file. The script connects via a raw TCP socket to the user-specified host and port and sends the crafted HTTP request. README specifies the tested environment (Windows 10 x86 build 16299, Sync Breeze Enterprise 10.0.28) and notes the exploit assumes mitigations like ASLR/CFG/DEP are disabled, and lists bad characters the shellcode must avoid.
Repository contains a single C proof-of-concept exploit for CVE-2017-14980 (Sync Breeze Enterprise 10.0.28) plus a README. Structure: - README.md: Describes the vulnerability (stack-based buffer overflow in the web authentication interface), affected version, and a lab setup (x86 Windows with ASLR/DEP disabled, no SafeSEH/stack cookies). - exploit.c: Standalone network exploit that opens a TCP socket to a hardcoded target (192.168.0.25:80) and sends a crafted HTTP POST request to /login. Exploit mechanics (exploit.c): - Builds an overflow buffer (exploit_buf[1024]) placed into the password form field. - Layout: 520 bytes of 'A' padding, then a 4-byte EIP overwrite (little-endian \x83\x0c\x09\x10 => 0x10090c83), followed by a 20-byte NOP sled, then embedded x86 shellcode. - Wraps the buffer into application/x-www-form-urlencoded POST data: "username=admin&password=<exploit_buf>". - Sends the request to the target and reads a response. Capabilities: - Remote, unauthenticated memory corruption leading to EIP control and execution of embedded shellcode (RCE) against the Sync Breeze Enterprise web service. Notable constraints: - Hardcoded IP/port and a fixed return address indicate the PoC is environment-specific and likely requires the same target version/build and memory layout assumptions (consistent with the README’s disabled mitigations).
Repository contains a single Python exploit (exploit.py) and documentation (readme.md) for CVE-2017-14980 affecting Sync Breeze Enterprise 10.0.28 on Windows 10 x86. The exploit performs an unauthenticated remote buffer overflow by sending a crafted HTTP POST request to the /login endpoint with Content-Type application/x-www-form-urlencoded. The request body overflows the username parameter: 780 bytes of padding followed by an EIP overwrite with a hardcoded jmp esp address (0x10090c83 in libspp.dll), then a small NOP sled and attacker-supplied shellcode read from a local file. The script connects via a raw TCP socket to the provided host/port and sends the constructed HTTP request. No vulnerability checking or response handling is implemented; it is a direct delivery PoC/operational exploit assuming disabled mitigations and correct shellcode constraints (bad chars listed in README).
Repository contains a single Python exploit (exploit.py) and documentation (readme.md) for CVE-2017-14980 affecting Sync Breeze Enterprise 10.0.28 on Windows 10 x86. The exploit is an unauthenticated remote buffer overflow delivered via an HTTP POST request to the /login endpoint with Content-Type application/x-www-form-urlencoded. It constructs a form body where the username parameter is padded with 780 bytes, overwrites EIP with a hardcoded jmp-esp address (0x10090c83 in libspp.dll), adds a small NOP sled, and appends attacker-supplied shellcode read from a local file. The script connects via a raw TCP socket to the provided host/port and sends the crafted HTTP request, aiming to achieve arbitrary code execution. The README explains the offset (EIP at byte 788), the gadget address, required disabled mitigations (ASLR/CFG/DEP), and shellcode bad characters.
This repository contains a proof-of-concept buffer overflow exploit for Sync Breeze Enterprise v10.0.28 (CVE-2017-14980). The exploit is implemented in C (exploit.c) and targets the /login HTTP endpoint by sending a specially crafted POST request with an overlong password field. The buffer overflow allows the attacker to overwrite EIP and execute arbitrary shellcode, which by default is a Windows x86 reverse shell (customizable by the user). The README.md provides detailed usage instructions, including how to generate shellcode with msfvenom and how to compile and run the exploit. The exploit requires network access to the target on port 8080 and may require adjustment of the EIP address and shellcode for successful exploitation. No detection scripts or fake elements are present; this is a functional exploit POC.
This repository contains a single Metasploit module (modules/exploits/windows/http/syncbreeze_bof.rb) that exploits a stack-based buffer overflow vulnerability (CVE-2017-14980) in the web interface of Sync Breeze Enterprise versions 9.4.28, 10.0.28, and 10.1.16 on Windows. The exploit targets the built-in web server by sending specially crafted HTTP GET or POST requests to endpoints such as '/' and '/login'. The module uses SEH overwrite and egghunter techniques to deliver a customizable Metasploit payload, resulting in remote code execution with elevated privileges. The module includes automatic target detection based on the product version and supports multiple versions with different offsets and return addresses. The exploit is operational and can be used to gain control of vulnerable Sync Breeze Enterprise installations accessible over the network.
This repository contains two exploit implementations (in C and Python) targeting Sync Breeze Enterprise v10.0.28 (CVE-2017-14980), a buffer overflow vulnerability in the web interface's /login endpoint. Both exploits craft a malicious HTTP POST request to the /login endpoint on the target (default IP: 10.30.30.180, port 80), overflowing the username parameter to overwrite the return address with a JMP ESP instruction (0x10090c83 in libspp.dll) and execute custom shellcode. The shellcode is a reverse shell payload, granting remote access to the attacker. The C version (42341_Sync_Breeze_Exploit.c) and Python version (syncbreeze_exploit.py) are functionally equivalent, with the Python script being more portable. The README simply names the exploit and CVE. The repository is operational, providing working exploit code and payloads, but is not weaponized for mass exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.