CVE-2017-17562

Confirmed PUBLISHED

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of...

Embedthis · GoAhead
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.1 High

At a Glance

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

nuclei_scanner cisa metasploit
CVE Published
Dec 12, 2017
Exploitation Reported
Dec 10, 2021
CVSS
8.1 High
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 43360 exploit-db.com · Exploit https://www.exploit-db.com/exploits/43360/
  • 43877 exploit-db.com · Exploit https://www.exploit-db.com/exploits/43877/
  • 1040702 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1040702
  • GitHub — elttam/advisories github.com · CVE Record https://github.com/elttam/advisories/tree/master/CVE-2017-17562
  • elttam.com.au/blog/goahead elttam.com.au · CVE Record https://www.elttam.com.au/blog/goahead/
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.