CVE-2018-8065 is a vulnerability in the web server component of Flexense SyncBreeze Enterprise 10.6.24. The vulnerability arises from a user mode write access violation in the syncbrs.exe process, which can be triggered by sending a rapid sequence of HTTP requests with excessively long HTTP header values or URIs. This suggests a lack of proper bounds checking or input validation in the handling of HTTP request data, leading to memory corruption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module targeting a denial of service (DoS) vulnerability (CVE-2018-8065) in the Flexense HTTP Server (version 10.6.24 and below). The exploit works by sending a large number of HTTP requests with oversized Accept headers to the target server, causing a user mode write access memory violation and crashing the service. The module allows configuration of the number of packets and the size of the Accept header. The exploit is operational and can be used to test or demonstrate the DoS vulnerability. The only code file is a Ruby script structured as a Metasploit module, and it does not provide shell access or code execution, but rather aims to crash the target service. The main network endpoints involved are the target's TCP port (default 80) and the Host header set to 127.0.0.1 in the HTTP requests.
This repository provides a denial of service (DoS) exploit targeting multiple Flexense products (including Sync Breeze Enterprise, DiskBoss Enterprise, and others) running the Flexense HTTP server version 10.6.24 or below. The vulnerability (CVE-2018-8065) is exploited by sending a large number of HTTP requests with oversized header fields, causing a user-mode memory violation and crashing the server process. The repository contains two main exploit implementations: a Metasploit auxiliary module (flexense_http_server_dos.rb) and a standalone Python script (dos.py). Both tools automate the process of sending malformed HTTP requests to the target server. The README and markdown documentation provide detailed usage instructions, affected product versions, and download links for the vulnerable software. The exploit is operational and can be used to reliably crash the target service, resulting in a denial of service condition.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.