PT-2026-102506 · Sliver C2 · Sliver C2
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Sliver C2 framework versions prior to 1.7.8
Description
An unhandled panic exists in the operator gRPC handler. An attacker controlling a compromised implant can crash the teamserver by returning a malformed or empty Download response. By sending zero-length or 1-3 byte data payloads through a hostile implant session, an out-of-bounds slice access is triggered in the
BinaryMagic() function of the vendored Binject library. This failure propagates through the operator gRPC interceptor chain and terminates the server process, disconnecting all operators.Recommendations
Update Sliver C2 framework to version 1.7.8 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sliver C2