PT-2026-52540 · Hydra · Hydra
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hydra versions prior to 9.7 commit 9cc84c2
Description
A stack buffer overflow exists in the NTLM authentication process across the SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules. The issue occurs when the software processes a malicious NTLM Type-2 challenge—a response from a server during the NTLM authentication handshake. A malicious server can send a crafted challenge containing an excessively long domain string, causing the base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes. This can enable remote code execution on systems that lack stack protection.
Recommendations
Update Hydra to the version containing commit 9cc84c2.
Exploit
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hydra