VYPR
High severity7.1NVD Advisory· Published Mar 2, 2017· Updated Jun 17, 2026

CVE-2017-5228

CVE-2017-5228

Description

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

Affected products

3
  • Rapid7/Metasploit3 versions
    cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*range: <=4.13.19
    • (no CPE)range: <4.13.0-2017020701
    • (no CPE)range: All versions prior to version 4.13.0-2017020701

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.