Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow
Vulnerability Description
Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable Windows systems.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-54330
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- a-rey
References
- https://www.exploit-db.com/exploits/51126
- https://web.archive.org/web/20200122082432/https://www.softsea.com/review/Inbit-Messenger-Basic-Edition.html
- https://github.com/a-rey/exploits/blob/main/writeups/Inbit_Messenger/v4.6.0/writeup.md
- https://www.vulncheck.com/advisories/inbit-messenger-unauthenticated-remote-seh-overflow
Affected Vendor
Inbit
View all reports →