← Back

CVE-2017-5229

nvd nist
Published: Mar 2, 2017Modified: May 13, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Exploitability: 1.6 / Impact: 5.5
Source: NVD

Description

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

Affected (1)

Products: Rapid7: Metasploit
1 product
Metasploit
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.13.19

Timeline

No history available yet.