Vulnerability record · CVE-2015-1171 · published 28 August 2015
CVE-2015-1171: GSM SIM Utility SIM Card Editor stack buffer overflow via .sms file
Gsm · Sim Card Editor
GSM SIM Utility (SIM Card Editor) 6.6 contains a stack-based buffer overflow (CWE-119) triggered by a long entry in a .sms file. Because the flaw is reachable over the network with no authentication and yields full confidentiality, integrity and availability impact, it is a serious code execution issue for anyone using this tool.
Description
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with full impact and has public exploits plus very high EPSS, though it is not in KEV and requires the victim to open a crafted .sms file.
What it is
GSM SIM Utility (SIM Card Editor) 6.6 contains a stack-based buffer overflow (CWE-119) triggered by a long entry in a .sms file. Because the flaw is reachable over the network with no authentication and yields full confidentiality, integrity and availability impact, it is a serious code execution issue for anyone using this tool.
Impact
An attacker can execute arbitrary code in the context of the user running SIM Card Editor, giving full control of the affected host. The CVSS 2.0 vector rates complete loss of confidentiality, integrity and availability.
Attack surface
The vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with low complexity and no authentication. The description states the trigger is a long entry in a .sms file, so exploitation requires the victim to open or process a crafted .sms file, implying some user interaction.
Exploitation
Public exploit references exist (Packet Storm, a blog post and a YouTube demonstration), and EPSS is 0.62663 (99.155th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.
What to do
- Upgrade GSM SIM Utility / SIM Card Editor beyond version 6.6 if a fixed release exists; the record does not name a patched version, so verify with the vendor.
- If no patch is available, stop using the tool to open .sms files from untrusted or external sources.
- Isolate the application so it runs with least privilege and cannot reach sensitive data or network resources.
- Apply email and web filtering to block or quarantine .sms attachments and downloads from untrusted origins.
- Treat .sms files as untrusted input and validate or sanitize them before processing.
Detection
- Monitor for crashes or abnormal process termination in SIM Card Editor when opening .sms files.
- Hunt for SIM Card Editor spawning child processes such as cmd.exe or powershell.exe, which would indicate successful code execution.
- Inspect email and file transfer logs for .sms attachments arriving from external or untrusted senders.
- Review endpoint telemetry for suspicious memory corruption behavior or shellcode-like activity in the SIM Card Editor process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1171 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1171), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.