VYPR
High severity7.1NVD Advisory· Published Mar 2, 2017· Updated May 13, 2026

CVE-2017-5231

CVE-2017-5231

Description

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

Affected products

2
  • cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*
    Range: <=4.13.19
  • Rapid7/Metasploitv5
    Range: All versions prior to version 4.13.0-2017020701

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.