A buffer overflow vulnerability exists in the control protocol of Flexense SyncBreeze Enterprise version 10.4.18. The vulnerability is triggered when a remote attacker sends a specially crafted packet to TCP port 9121, leading to a buffer overflow condition. This can allow the attacker to overwrite memory and potentially execute arbitrary code on the target system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2018-6537 affecting Flexense Sync Breeze 10.4.18 on Windows 10 x86. The repository contains only two files: exploit.py, which implements the exploit logic, and readme.md, which documents the vulnerability, exploitation method, constraints, and usage. The main exploit capability is unauthenticated remote code execution over a TCP connection. The script accepts three required command-line arguments: --host, --port, and --file. It reads attacker-supplied raw shellcode from the specified local file, prepends a 16-byte NOP sled, pads the shellcode region to 400 bytes, and embeds it into a larger crafted buffer designed to trigger an SEH overwrite. The buffer layout includes 124 bytes of padding, an NSEH value of 0x06eb9090, an SEH overwrite value of 0x1015a2f0, short stack-adjust/jump instructions, additional NOP padding, and finally the shellcode block. The comments and README indicate the SEH gadget at 0x1015a2f0 is a pop/pop/ret sequence used to regain control after the exception handler overwrite, followed by stack alignment and a jump to ESP to reach the shellcode. The send routine constructs a custom binary header before transmitting the payload. It then opens a TCP socket and sends header + buffer directly to the target service. No authentication, staging, callback, or secondary infrastructure is present in the code. There are no hardcoded IPs, domains, URLs, or registry keys; the only network target is the operator-supplied host and port. The only file-system observable is the local shellcode file path provided by the user. Operationally, this is an exploit rather than a scanner or detector. It does not verify target version or vulnerability status before sending the payload. It is best classified as OPERATIONAL: it performs real exploitation and supports arbitrary payloads, but payload generation/customization is external to the script and not integrated into a larger framework. The README further clarifies environmental assumptions: mitigations such as ASLR and DEP should be disabled, and shellcode must avoid bad characters \x00, \x02, \x0A, and \x0D.
Repository contains a single Python exploit (exploit.py) and documentation (readme.md) for CVE-2018-6537 against Flexense Sync Breeze v10.4.18 on Windows 10 x86. Core behavior: - Reads attacker-provided shellcode bytes from a local file (--file). - Constructs an SEH overflow buffer: - Prepends a 16-byte NOP sled to the shellcode and pads it with 'A' to a 400-byte shellcode region. - Builds an overall payload with 124 'A's, then overwrites NSEH with 0x06eb9090 (short jump + NOPs) and SEH with 0x1015a2f0 (pop/pop/ret). - Adds stack alignment and control-transfer stubs (including an ESP adjustment and a jmp to a register/ESP) and pads to ~1000 bytes before appending the shellcode region. - Wraps the overflow buffer in a custom binary header (fixed magic bytes plus length fields) and sends it over a TCP connection to the specified host/port. Exploit capability and intent: - Unauthenticated remote code execution via a network-reachable Sync Breeze service by triggering an SEH-based stack overflow and redirecting execution into the supplied shellcode. Notable constraints/assumptions (from README and code): - Assumes mitigations disabled (ASLR/CFG/DEP) and a specific Windows 10 x86 build. - Shellcode size is effectively limited to ~400 bytes in the current layout. - Bad characters to avoid when generating shellcode: \x00\x02\x0A\x0D. Repository structure/purpose: - exploit.py: standalone command-line exploit tool (argparse) that delivers the crafted TCP payload. - readme.md: explains the SEH overwrite strategy (PPR, jump over SEH, stack alignment, jmp esp) and provides usage instructions.
Repository contains a single Python exploit (exploit.py) and documentation (readme.md) for CVE-2018-6537 targeting Sync Breeze 10.4.18 on Windows 10 x86. The exploit is an unauthenticated remote SEH overflow delivered over a TCP connection. Core logic: - CLI requires --host, --port, --file. - Reads raw shellcode from the provided file, prepends a small NOP sled, and pads it to a 400-byte region. - Constructs an SEH overwrite buffer: 124 bytes padding, NSEH set to 0x06eb9090 (short jump over SEH), SEH set to 0x1015a2f0 (POP/POP/RET gadget), followed by stack adjustment (add sp/esp by 0x0e70) and a jmp esp (\xff\xe4) to land in the NOP sled/shellcode. - Wraps the overflow buffer in a custom binary header (starts with bytes 75 19 ba ab and includes length fields) and sends it to the target via a TCP socket. Notable constraints from README: - Assumes mitigations disabled (ASLR/CFG/DEP). - Bad characters to avoid in shellcode: \x00 \x02 \x0A \x0D. No hardcoded C2/reverse-shell endpoints are present; the network target is entirely user-specified via host/port, and payload behavior depends on the supplied shellcode.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.