IPass Control Pipe Remote Command Execution

This Metasploit module exploits a vulnerability in the IPass Client service. This service provides a named pipe which can be accessed by the user group BUILTINUsers. This pipe can be abused to force the service to load a DLL from a SMB share.

Leave a Reply