CyberRota Analysis
AI-GeneratedThe vulnerability affects the ManageSieve service, allowing authenticated attackers to exploit an out-of-bounds write through a specially crafted Sieve script, leading to memory corruption and potential denial of service. This issue may also open the door for remote code execution under certain conditions. Organizations utilizing the ManageSieve service should prioritize addressing this vulnerability by disabling the service if not needed and updating to a secure version.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.