WinAPRS 2.9.0 contains a buffer overflow in its VHF KISS TNC component. A remote attacker can send malicious AX.25 packets over the air to trigger the overflow and achieve remote code execution. The affected product is no longer supported by its maintainer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a multi-stage exploit for CVE-2022-24702, targeting the WinAPRS application on Windows XP SP3 and Windows 10. The exploit is delivered over a serial port using the KISS protocol, with Python scripts and C++ code orchestrating the attack. The structure is organized by OS version, with separate directories for Windows 10 and Windows XP SP3, each containing heap spray scripts, shellcode stages (in Python), and main exploit scripts. The exploit works by first grooming the heap of the target process (WinAPRS) via serial port, then sending specially crafted KISS packets containing shellcode. The shellcode is delivered in three stages: the first triggers a SEH handler overflow and injects the second stage into explorer.exe; the second stage locates and opens a serial port, reads the third stage, and executes it; the third stage establishes a reverse shell by spawning cmd.exe and redirecting its input/output over the serial port. The C++ file (revShellTestXp.cpp) demonstrates the reverse shell mechanism for XP. The exploit requires physical or logical access to the serial port and is not a remote network exploit. The code is operational and provides a working reverse shell if the target is properly configured and vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.