CVE-2017-17562
Embedthis GoAhead: Remote Code Execution
As of , CVE-2017-17562 in Embedthis GoAhead is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 10 December 2021
- US federal deadline
- 10 June 2022182 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.96Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
- Public exploit
- 1 Metasploit module and 2 Exploit-DB entries (2 verified)
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
CISA's description
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.
The CVE record's description, from mitre
- CVE published
- 12 December 2017
- Assigned by
- mitre
- CVSS
- 8.1 High (CVSS 3.1, from CISA-ADP)
- CWE-20
- Improper Input Validation
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 43360).
- Exploit-DB published an exploit (EDB-ID 43877).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: GoAhead Web Server LD_PRELOAD Arbitrary Module Loadexploit module, rank excellent
- Exploit-DB: GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Arbitrary Module Load (Metasploit)EDB-ID 43877, verified by Exploit-DB, 24 January 2018
- Exploit-DB: GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Remote Code ExecutionEDB-ID 43360, verified by Exploit-DB, 18 December 2017
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org