← Vulnerability feed

Vulnerability record · CVE-2007-6377 · published 15 December 2007

CVE-2007-6377: BadBlue ext.dll PassThru stack buffer overflow

BBadblue · Badblue

BadBlue 2.72b and earlier contains a stack-based buffer overflow in the PassThru functionality of ext.dll, triggered by a long query string. A remote, unauthenticated attacker can send a crafted request to overwrite stack memory and potentially execute arbitrary code on the server.

7.5 CVSS 2.0 High EPSS 66% · top 0.7% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with public exploit code and very high EPSS, though the product is legacy and no longer vendor-supported.

What it is

BadBlue 2.72b and earlier contains a stack-based buffer overflow in the PassThru functionality of ext.dll, triggered by a long query string. A remote, unauthenticated attacker can send a crafted request to overwrite stack memory and potentially execute arbitrary code on the server.

Impact

Successful exploitation allows remote code execution in the context of the BadBlue web server process, giving the attacker control of the host. Even without code execution, the overflow can crash the service, causing denial of service.

Attack surface

The flaw is reached over the network through the PassThru functionality in ext.dll via an HTTP query string. Per the CVSS vector AV:N/AC:L/Au:N, no authentication and no user interaction are required.

Exploitation

CISA KEV does not list this CVE, but public proof-of-concept and exploit references exist and EPSS is very high (0.664, 99th percentile), indicating elevated likelihood of exploitation attempts.

What to do

  • Upgrade or replace BadBlue 2.72b and earlier; the vendor no longer maintains the product, so migrate to a supported web server.
  • If BadBlue must remain, restrict network access to the service with firewall rules and place it behind a reverse proxy that filters oversized query strings.
  • Disable or remove the ext.dll PassThru functionality if it is not required.
  • Run the BadBlue service under a low-privilege account to limit the impact of code execution.

Detection

  • Monitor web server logs for unusually long or malformed query strings targeting ext.dll or PassThru paths.
  • Alert on BadBlue process crashes or restarts that correlate with inbound HTTP requests.
  • Use network IDS signatures for known BadBlue overflow exploit patterns and monitor for shellcode-like payloads in query strings.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6377 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2008-2003Badblue permissions and access controls vulnerabilityBadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackers to (1…EPSS 2.8%7.5CVE-2007-6378Badblue path traversal vulnerabilityDirectory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. …EPSS 3.2%5.0CVE-2007-6379Badblue vulnerabilityBadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation pat…EPSS 3.3%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2007-6377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.