CVE-2025-34105

A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can trigger a buffer overflow, potentially leading to arbitrary code execution with SYSTEM privileges on vulnerable Windows hosts.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2025, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://vulncheck/advisories/diskboss-enterprise-buffer-overflow-rce', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/diskboss-enterprise-buffer-overflow-rceĀ -

15 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-15 13:15

Updated : 2025-07-15 20:07


NVD link : CVE-2025-34105

Mitre link : CVE-2025-34105

CVE.ORG link : CVE-2025-34105


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-787

Out-of-bounds Write