Vulnerability record · CVE-2018-8065 · published 12 March 2018
CVE-2018-8065: Flexense SyncBreeze Enterprise web server input validation DoS
Flexense · Syncbreeze
The SyncBreeze Enterprise 10.6.24 web server mishandles HTTP input, causing a user mode write access violation in the syncbrs.exe memory region. Rapidly sending requests with long HTTP header values or long URIs crashes the service, disrupting availability.
Description
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be triggered by rapidly sending a variety of HTTP requests with long HTTP header values or long URIs.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with no authentication or user interaction required and a very high EPSS score, though impact is limited to denial of service.
What it is
The SyncBreeze Enterprise 10.6.24 web server mishandles HTTP input, causing a user mode write access violation in the syncbrs.exe memory region. Rapidly sending requests with long HTTP header values or long URIs crashes the service, disrupting availability.
Impact
An unauthenticated remote attacker can crash the SyncBreeze web server process, causing a denial of service. No data confidentiality or integrity impact is indicated by the CVSS vector.
Attack surface
Reachable over the network through the SyncBreeze HTTP web server; the CVSS vector shows no privileges or user interaction required. The flaw is triggered by crafted HTTP requests with oversized headers or URIs.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.75875, 99.5th percentile) and public references include a Packet Storm advisory, a GitHub PoC, and a Metasploit pull request, indicating public exploit tooling exists.
What to do
- Upgrade SyncBreeze Enterprise to a version later than 10.6.24 if the vendor provides a fix; no fixed version is stated in this record.
- If patching is not possible, restrict network access to the SyncBreeze web server to trusted hosts only.
- Place the web server behind a reverse proxy or WAF that rejects oversized HTTP headers and URIs.
- Monitor the syncbrs.exe process and configure automatic restart or alerting on crash.
- Review vendor advisories for an official fix, since this record does not name one.
Detection
- Alert on syncbrs.exe process crashes or unexpected restarts in Windows event logs.
- Monitor HTTP request logs for unusually long header values or URIs targeting the SyncBreeze web server.
- Watch for high-volume or rapid HTTP request bursts from a single source to the SyncBreeze service.
- Use the public PoC and Metasploit module references to build test signatures for known exploit traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172676/Flexense-HTTP-Server-10.6.24-Buffer-Overflow-Denial-Of-Service.html | |
| https://github.com/EgeBalci/Sync_Breeze_Enterprise_10_6_24_-DOS | Third Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/9701 | Issue TrackingThird Party Advisory |
| http://packetstormsecurity.com/files/172676/Flexense-HTTP-Server-10.6.24-Buffer-Overflow-Denial-Of-Service.html | |
| https://github.com/EgeBalci/Sync_Breeze_Enterprise_10_6_24_-DOS | Third Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/9701 | Issue TrackingThird Party Advisory |
Track CVE-2018-8065 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.