CVE-2020-37001
8.4Frigate · Professional
Frigate Professional 3.36.0.9 contains a local stack-based buffer overflow in the Pack File feature, allowing attackers to execute arbitrary code via a malicious input payload.
Executive summary
A local buffer overflow vulnerability in Frigate Professional 3.36.0.9 allows attackers to achieve remote code execution by leveraging a crafted payload in the Pack File feature.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring in the Pack File feature. An attacker can supply a malicious string to the "Archive To" input field, which overwrites the Structured Exception Handler (SEH) to redirect execution flow and trigger a reverse shell.
Business impact
Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the application user. This could lead to a complete compromise of the local machine, unauthorized data access, or the deployment of persistent malware. Given the CVSS score of 8.4, this vulnerability represents a high-risk scenario for organizations relying on this software for file management tasks.
Remediation
Immediate Action: Discontinue the use of Frigate Professional version 3.36.0.9 until a verified security patch is provided by the vendor, or upgrade to a version confirmed by the vendor to be free of this flaw.
Proactive Monitoring: Monitor system logs for unexpected application crashes and inspect endpoint security telemetry for suspicious reverse shell connections originating from the Frigate process.
Compensating Controls: Since this is a local attack, restrict user permissions to prevent unauthorized execution of the application and utilize endpoint detection and response (EDR) solutions to block suspicious child processes spawned by the software.
Exploitation status
Public Exploit Available: Yes, a functional local exploit is available via the Exploit Database (EDB-ID 48688).
Analyst recommendation
The presence of a publicly available exploit makes this vulnerability a significant risk for any environment still running the affected software version. Security teams should prioritize the identification of all instances of Frigate Professional 3.36.0.9 and immediately apply patches or restrict access to the application to prevent potential code execution attacks.
More Frigate CVEs
Sources
Originally found and disclosed by MasterVlad, per the CVE Program record.
- ExploitDB-48688 Exploit / PoC
- Archived Vendor Homepage
- VulnCheck Advisory: Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter) Third-party advisory