CVE-2025-34096 is a stack-based buffer overflow in Easy File Sharing HTTP Server version 7.2. The vulnerability is triggered by sending a crafted HTTP POST request to the /sendemail.ghp endpoint with an overly long Email parameter. The application does not properly validate the length of the Email field before copying or processing it on the stack, leading to memory corruption. Because the vulnerable endpoint is reachable over HTTP and no authentication is required according to the provided information, a remote attacker can exploit the flaw to achieve arbitrary code execution in the context of the server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a structured exploit-development walkthrough for CVE-2025-34096, targeting Easy File Sharing Web Server 7.2 on Windows. It is not part of a larger exploit framework; instead, it contains standalone Python 3 scripts and Markdown documentation that progressively build a working SEH-based remote code execution exploit against the unauthenticated password recovery endpoint POST /sendemail.ghp. Repository structure: the top-level README explains the vulnerability, affected product, attack surface, and exploitation rationale. The Vulnerability/README.md file provides the step-by-step methodology. The Vulnerability/Exploit/ directory contains eight Python scripts representing successive exploit-development stages: (1) basic connectivity and valid POST request, (2) fuzzing oversized Email input, (3) cyclic-pattern SEH offset discovery, (4) confirmation of nSEH/SEH control at offset 4060, (5) validation of a POP POP RET gadget in ImageLoad.dll at 0x100194b2, (6) use of an nSEH short jump to reach controlled data after the SEH record, (7) bad character testing, and (8) final shellcode delivery. Main exploit capability: the code sends crafted raw HTTP POST requests over a TCP socket to port 80 and abuses the Email parameter in /sendemail.ghp to overflow a stack buffer and overwrite the SEH chain. The final exploit uses a classic SEH technique: padding to the nSEH offset, a short jump in nSEH, a POP POP RET gadget in SEH, a NOP sled, and embedded Windows shellcode. This provides unauthenticated remote code execution in the target server process. Notable technical details extracted from the code and docs: target defaults to 127.0.0.1:80 in all scripts; the vulnerable parameter is Email; the offset to nSEH is 4060 bytes; the chosen SEH gadget is 0x100194b2 in ImageLoad.dll; and the documentation lists bad characters including 0x00, 0x0a, 0x0d, 0x20, 0x22, 0x25, 0x26, 0x2b, 0x2c, 0x2e, 0x2f, 0x3a, 0x3d, 0x5c, 0x7e, and 0xff. The docs also mention optional DEP bypass via a ROP chain calling VirtualProtect, but no implemented ROP exploit is included in the code shown. Overall, this is a real exploit repository with educational intent: it teaches the full workflow for developing an SEH overflow exploit while still containing a functional final exploit script capable of delivering shellcode to the vulnerable service.
This repository contains a single Metasploit module (modules/exploits/windows/http/easyfilesharing_post.rb) that exploits a buffer overflow vulnerability (CVE-2025-34096) in Easy File Sharing HTTP Server version 7.2. The exploit targets the '/sendemail.ghp' HTTP endpoint by sending a specially crafted POST request containing a large payload that overflows a buffer, overwrites the return address, and executes a ROP chain to bypass DEP, followed by user-supplied shellcode (Metasploit payload). The module is fully integrated with Metasploit, allowing the user to select and deliver a variety of payloads (such as reverse shells or Meterpreter sessions). The exploit requires network access to the target server on TCP port 80. The code is mature and weaponized, leveraging Metasploit's payload and handler infrastructure. The only file in the repository is the exploit module itself, written in Ruby.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.