Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-12561 — Reverse-engineering write-up and proof of concept for CVE-2017-12561, a use-after-free in HPE iMC dbman, covering binary diffing, ASN.1 decoding, and crash analysis. | Kitploit
Tools/GitHubGitHub/parapapinho/cve-2017-12561
Memory ForensicsVulnerability AnalysisExploitationReverse EngineeringBinary AnalysisPapers & Research
GitHubparapapinho/cve-2017-12561

CVE-2017-12561

Reverse-engineering write-up and proof of concept for CVE-2017-12561, a use-after-free in HPE iMC dbman, covering binary diffing, ASN.1 decoding, and crash analysis.

View Repository
11 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-12561 - HPE iMC dbman Use-After-Free

Technical analysis of CVE-2017-12561, a use-after-free vulnerability in the dbman service of Hewlett Packard Enterprise Intelligent Management Center (iMC).

Overview

The vulnerability affects the service's handling of opcode 10012. Incorrect object lifetime management allows a previously freed object to be accessed again, resulting in memory corruption.

According to ZDI-17-836, the flaw is reachable without authentication and can allow remote code execution with SYSTEM privileges. The dbman service listens on TCP port 2810 by default.

About this research

This repository contains my reverse-engineering write-up and accompanying proof of concept. The analysis covers:

  • Binary comparison using IDA and Diaphora to examine changes between vulnerable and patched binaries.
  • Analysis of the service's command handling and ASN.1/BER decoding.
  • Debugging of the crash and investigation of object cleanup and subsequent reuse in the ACE event-handling lifecycle.

The documented testing was performed on Windows Server 2008 R2 Datacenter x64. The write-up demonstrates a crash and investigates its use-after-free root cause; it does not demonstrate a complete remote code execution exploit.

Write-up

Read the full technical analysis.

Credits and references

  • Reverse engineering and write-up: Filipe Oliveira (Everdoh).
  • Original vulnerability discovery: Steven Seeley (mr_me) of Offensive Security, as credited by ZDI.
  • Advisory: ZDI-17-836, published October 3, 2017.
Download Tool