# Inbit Messenger 4.9.0 远程命令执行漏洞
## 概述
Inbit Messenger 4.6.0 至 4.9.0 存在远程命令执行漏洞,攻击者可通过利用信使协议中的栈溢出漏洞,在未认证的情况下执行任意命令。
## 影响版本
4.6.0 ≤ Inbit Messenger < 4.9.0
## 细节
漏洞源于对XML数据包的处理不当,攻击者可向目标系统10883端口发送特制的XML数据包,触发栈溢出,从而执行恶意负载。
## 影响
攻击者可利用该漏洞以系统权限执行任意命令,完全控制受影响系统。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: Inbit Messenger v4.9.0 - Unauthenticated Remote Command Execution (RCE) - Windows remote Exploit -- 🔗来源链接
标签:exploit
神龙速读:
- **漏洞标题**: Inbit Messenger v4.9.0 - Unauthenticated Remote Command Execution (RCE)
- **EDB-ID**: 51127
- **Author**: a-rey
- **Type**: REMOTE
- **Platform**: WINDOWS
- **Date**: 2023-03-29
- **EDB Verified**: ×
- **Exploit**: / {}
- **Vulnerable App**: Inbit Messenger
- **关键信息**
- **漏洞版本**: v4.6.0 - v4.9.0
- **影响平台**: Windows XP SP3, Windows 7, Windows 10, Windows Server 2019
- **漏洞分类**: Unauthenticated Remote Command Execution (RCE)
- **发布时间**: 2022-08-11
- **作者**: a-rey
- **引用**: ExploitDB
标题: exploits/writeups/Inbit_Messenger/v4.6.0/writeup.md at main · a-rey/exploits · GitHub -- 🔗来源链接
标签:technical-description
标题: Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE) | Advisories | VulnCheck -- 🔗来源链接
标签:third-party-advisory
神龙速读:
- **Title**: Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE)
- **Severity**: Critical
- **Date**: January 13, 2026
- **Affected**: Inbit Messenger <= 4.9.0
- **CVE ID**: CVE-2023-54329
- **CWE ID**: CWE-121 Stack-based Buffer Overflow
- **CVSS Score**: 9.8 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **References**:
- ExploitDB-51127
- Archived Software Download Page
- Exploit Write-Up
- **Credit**: a-rey
- **Description**: Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.