Security Advisory
CVE-2020-37001
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the Archive To input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.