
Reverse-engineering write-up and proof of concept for CVE-2017-12561, a use-after-free in HPE iMC dbman, covering binary diffing, ASN.1 decoding, and crash analysis.
Technical analysis of CVE-2017-12561, a use-after-free vulnerability in the dbman service of Hewlett Packard Enterprise Intelligent Management Center (iMC).
The vulnerability affects the service's handling of opcode 10012. Incorrect object lifetime management allows a previously freed object to be accessed again, resulting in memory corruption.
According to ZDI-17-836, the flaw is reachable without authentication and can allow remote code execution with SYSTEM privileges. The dbman service listens on TCP port 2810 by default.
This repository contains my reverse-engineering write-up and accompanying proof of concept. The analysis covers:
The documented testing was performed on Windows Server 2008 R2 Datacenter x64. The write-up demonstrates a crash and investigates its use-after-free root cause; it does not demonstrate a complete remote code execution exploit.
Read the full technical analysis.