CVE-2017-17932
Description
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.
In plain language
AI Worth attentionIf you run ALLPlayer ALLMediaServer (MediaServer.exe) version 0.95 or earlier, attackers on the network can crash it or potentially take control by sending a long message to TCP port 888—so you should act soon.
CVE-2017-17932 is a network-triggered buffer overflow in MediaServer.exe (ALLPlayer ALLMediaServer) caused by failing to properly validate incoming message length before copying to memory; remote, unauthenticated attackers can send an overly long string to TCP port 888 to crash the service or execute arbitrary code.
What to do now
- Check whether ALLPlayer ALLMediaServer is installed and running, and confirm the MediaServer.exe version is 0.95 or earlier.
- If it is affected, block incoming connections to TCP port 888 from the internet (and untrusted networks) using your firewall.
- Temporarily stop or disable MediaServer.exe / ALLMediaServer until you can apply the vendor’s update.
- Contact the software vendor (or your reseller) to obtain the update that removes CVE-2017-17932 and schedule it for the next maintenance window.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-17932 and every CVE in our database. Create a free account — no credit card required.
Create Free Account