CVE-2019-6250 is a pointer/integer overflow vulnerability in ZeroMQ libzmq (0MQ) versions 4.2.x and 4.3.x before 4.3.1, specifically in the v2_decoder.cpp file within the zmq::v2_decoder_t::size_ready function. An authenticated attacker can trigger an integer overflow, leading to a buffer overflow that allows writing arbitrary data beyond the buffer's bounds. Due to the memory layout, this can be exploited to inject OS commands into adjacent data structures, enabling arbitrary code execution without traditional control flow hijacking.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a complete lab and exploit kit for CVE-2019-6250, a pre-auth heap buffer overflow in ZeroMQ libzmq’s ZMTP/2.0 decoder path. It is not a framework module; the main exploit is exploit.py, supported by a minimal vulnerable target (server.c), provisioning scripts (setup.sh, start_server.sh), an address-profile helper (read_addresses.sh), a smoke test (run_lab_test.sh), and a Dockerfile that builds a reproducible Debian-based lab with libzmq v4.3.0. Core exploit capability: exploit.py performs unauthenticated network exploitation over TCP against a ZeroMQ listener. It sends a crafted 12-byte ZMTP/2.0 greeting, then a LARGE frame header with msg_size set to 0xFFFFFFFFFFFFFFFF to trigger integer/pointer arithmetic wraparound in libzmq’s bounds check. It follows with an 8224-byte payload that overruns the receive buffer into adjacent content_t metadata, replacing the function pointer field (ffn) with the address of libc system() and pointing the data field at an attacker-controlled command string embedded in the payload. When the TCP connection is closed, the target’s decoder teardown path calls the overwritten function pointer, resulting in system(cmd) execution in the server process. The exploit is operational rather than a bare PoC because it includes a working command-execution chain and examples for both proof-file creation and reverse-shell/connect-back behavior. However, it is highly environment-specific: the default profile hardcodes libc base, system offset, and read_pos for the bundled lab image with ASLR disabled. The helper script read_addresses.sh exists to regenerate those values for a different but still controlled lab image. Repository structure and purpose: - exploit.py: primary exploit implementation in Python. - server.c: minimal ZeroMQ PULL listener used as the vulnerable target harness. - setup.sh: clones/builds libzmq 4.3.0 and compiles the target harness; disables ASLR. - start_server.sh: launches the vulnerable server on tcp://0.0.0.0:5555. - read_addresses.sh: derives libc base/system offset/read_pos from the running target for profile regeneration. - run_lab_test.sh: validates both file-creation and connect-back execution paths. - Dockerfile: creates a reproducible containerized lab environment. - screenshots/*.txt and README.md: documentation and captured proof output. Fingerprintable targets and endpoints are primarily local lab artifacts and network listeners: the exploit targets host:port (default 127.0.0.1:5555), the server binds tcp://0.0.0.0:5555, and reverse-shell demonstrations connect back to 127.0.0.1:4444. Important file artifacts include /tmp/PWNED-CVE-2019-6250, /opt/zmq-rce/profile.json, /opt/zmq-rce/srv.log, /proc/$PID/maps, and /usr/lib/x86_64-linux-gnu/libc.so.6. Overall, this is a real exploit repository intended for defensive research and lab reproduction of CVE-2019-6250, demonstrating pre-auth remote command execution against vulnerable libzmq with a deterministic, lab-tuned function-pointer hijack chain.
This repository provides a proof-of-concept (PoC) exploit for CVE-2019-6250, a critical integer overflow vulnerability in ZeroMQ's libzmq (specifically in src/v2_decoder.cpp). The exploit consists of a single C++ file (main.cpp) that demonstrates how to trigger the vulnerability by sending a specially crafted message to a ZeroMQ REP socket bound to tcp://*:6666. The exploit leverages the integer overflow to overwrite a function pointer in the content_t structure, allowing arbitrary code execution. The PoC shows how to use this to execute arbitrary functions, such as strcpy and system, on the target. The README.md provides detailed background, build instructions, and an explanation of the vulnerability and exploitation method. The exploit is operational and demonstrates real code execution, but is not weaponized for remote exploitation beyond the local demonstration. The main fingerprintable endpoints are the TCP socket on port 6666 and the use of localhost (127.0.0.1).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.