Lucene search

K
osvGoogleOSV:GHSA-MJ63-64X7-57XF
HistoryJun 18, 2021 - 6:43 p.m.

Path traversal in impacket

2021-06-1818:43:14
Google
osv.dev
28
impacket
smbserver
path traversal
vulnerabilities
arbitrary code execution
software security

EPSS

0.014

Percentile

86.5%

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket before 0.9.23. An attacker that connects to a running smbserver instance can list and write to arbitrary files via …/ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.

References