IBM Tivoli Endpoint 4.1.1 Buffer Overflow / Hard-Coded Credentials

0
75

IBM Tivoli Endpoint version 4.1.1 remote SYSTEM exploit that leverages hard-coded base64 encoded authentication credentials in lcfd.exe and a stack-based buffer overflow when parsing HTTP variable values. Spawns a reverse shell to port 4444.

Source: IBM Tivoli Endpoint 4.1.1 Buffer Overflow / Hard-Coded Credentials