EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.
An attacker sends a GET request to the chat.ghp endpoint, passing an excessively long value in the username parameter. The buffer overflow (CWE-787: out-of-bounds write) allows overwriting the application's memory. In the crafted payload, the attacker places shellcode and ROP (Return-Oriented Programming) gadgets, which enables hijacking the execution flow and executing arbitrary code in the context of the server process.
An attacker can remotely execute arbitrary code (RCE) in the context of the EChat Server application without any authentication, which can lead to full compromise of the server.
Patches available from the vendor should be applied in accordance with the references. Due to the publicly available exploit (Exploit-DB 44155), it is recommended to prioritize decommissioning or network isolation of vulnerable instances until the patch is deployed.
EChat Server (Easy Chat Server) version 3.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEchatserver Easy Chat Server
APPEchatserver≤ 3.1
Related vulnerabilities
RCE via stack-based buffer overflow w Easy Chat Server (SEH)
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the appl...
Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the comp...
An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message p...
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary p...