CVE-2018-6892
CRITICALAn issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Affected Products
synccloudmeResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
by Matteo Malvica · Jan 28, 2019
Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit)
by Raymond Wellnitz · Aug 14, 2018
CloudMe Sync < 1.11.0 - Buffer Overflow
by hyp3rlinx · Feb 13, 2018
CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR)
by boku · Sep 29, 2020
CloudMe Sync 1.10.9 - Stack-Based Buffer Overflow (Metasploit)
by Metasploit · Feb 26, 2018
Frequently Asked Questions
Is CVE-2018-6892 in your stack?
O3 detects CVE-2018-6892 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.