CVE-2017-9544
9.8
CRITICAL · CVSS 3.1 · EPSS 24.1% (pctl 98)
Patch early
EPSS 24.1% — above the 10% action threshold.
Description
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 24.12% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-06-12 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| echatserver | easy chat server |
→ the Explorer · watch your stack · NVD