Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102507— Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC

Quick assessment

Affected
BishopFox sliver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sliver C2 框架 1.7.7 及更早版本存在一个未处理的 panic 漏洞,位于操作员 gRPC 处理程序中。攻击者若控制了已被攻陷的植入体(implant),可以通过返回畸形或空的 Download 响应,导致整个 teamserver 崩溃。 具体来说,攻击者可以通过恶意的植入体会话发送零长度或仅包含 1 至 3 字节的数据载荷,从而触发 vendored 的 Binject 库中 BinaryMagic 函数发生的越界切片访问异常。该异常在操作员 gRPC 拦截器链中未被捕获和恢复,最终导致服务器进程

CVSS 5.7 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102507

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC
Source: CVE Program / CVE List V5
Vulnerability Description
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
BishopFox sliver 1.1.0 ~ 1.7.7 -

II. Public POCs for CVE-2026-102507

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102507

请登录查看更多情报信息。

Other References for CVE-2026-102507 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102507

No comments yet


Leave a comment