module
IBM Lotus Domino iCalendar MAILTO Buffer Overflow
Disclosed | Created |
---|---|
Sep 14, 2010 | May 30, 2018 |
Disclosed
Sep 14, 2010
Created
May 30, 2018
Description
This module exploits a vulnerability found in IBM Lotus Domino iCalendar. By
sending a long string of data as the "ORGANIZER;mailto" header, process "nRouter.exe"
crashes due to a Cstrcpy() routine in nnotes.dll, which allows remote attackers to
gain arbitrary code execution.
Note: In order to trigger the vulnerable code path, a valid Domino mailbox account
is needed.
sending a long string of data as the "ORGANIZER;mailto" header, process "nRouter.exe"
crashes due to a Cstrcpy() routine in nnotes.dll, which allows remote attackers to
gain arbitrary code execution.
Note: In order to trigger the vulnerable code path, a valid Domino mailbox account
is needed.
Authors
A. Plaskett
sinn3r sinn3r@metasploit.com
sinn3r sinn3r@metasploit.com
Platform
Windows
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.