← Back to CVE List

CVE-2017-5229

Published: 2017-03-02T20:59Z
Last Modified: 2024-11-21T03:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt