CVE-2017-11517 describes a critical stack-based buffer overflow vulnerability in GCoreServer.exe within Geutebrueck Gcore versions 1.3.8.42 and 1.4.2.37. This flaw allows remote, unauthenticated attackers to execute arbitrary code on affected servers by sending a specially crafted, long URI in a GET request. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog or Hot List, and with no evidence of active exploitation, a Metasploit module and an ExploitDB entry confirm readily available exploit code, indicating a high potential for exploitation. Despite the high risk, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.8.42CPE matchmatch criteria | cpe:2.3:a:geutebrueck:gcore:1.3.8.42:*:*:*:*:*:*:* | ||
1.4.2.37CPE matchmatch criteria | cpe:2.3:a:geutebrueck:gcore:1.4.2.37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.