High severity7.1NVD Advisory· Published Mar 2, 2017· Updated May 13, 2026
CVE-2017-5228
CVE-2017-5228
Description
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Affected products
2- Rapid7/Metasploitv5Range: All versions prior to version 4.13.0-2017020701
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.