DiskBoss Enterprise Stack-Based Buffer Overflow RCE
Vulnerability Description
A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34105
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- vportal
- Ahmad Mahfouz
References
More from Flexense
View All →Affected Vendor
Flexense
View all reports →