← Vulnerability feed

Vulnerability record · CVE-2022-28381 · published 3 April 2022

CVE-2022-28381: ALLMediaServer Mediaserver.exe stack buffer overflow via TCP port 888

Allmediaserver · Allmediaserver

ALLMediaServer 1.6 contains a stack-based buffer overflow in Mediaserver.exe reachable over TCP port 888, where a long string overwrites stack memory. It is a related issue to CVE-2017-17932, indicating the same class of flaw was not fully fixed. Successful exploitation allows remote code execution on the host running the media server.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 10.0
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit code plus very high EPSS make this an urgent exposure for any host running ALLMediaServer 1.6.

What it is

ALLMediaServer 1.6 contains a stack-based buffer overflow in Mediaserver.exe reachable over TCP port 888, where a long string overwrites stack memory. It is a related issue to CVE-2017-17932, indicating the same class of flaw was not fully fixed. Successful exploitation allows remote code execution on the host running the media server.

Impact

An unauthenticated remote attacker can execute arbitrary code in the context of the Mediaserver.exe process, giving full control of that service and potentially the underlying host. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reachable over the network via TCP port 888 with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any host exposing the ALLMediaServer service on that port is directly exposed.

Exploitation

Public exploit code is referenced in Packet Storm and a GitHub repository, and EPSS is 0.70405 (99.355th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded there.

What to do

  • Upgrade ALLMediaServer to a version later than 1.6 if the vendor has released a fix; the record does not name a patched version, so confirm with the vendor.
  • If no patch exists, remove or disable the ALLMediaServer service on any internet-facing or untrusted network segment.
  • Block or restrict inbound TCP port 888 to trusted hosts only, and place the service behind a firewall or VPN.
  • Run the service under a low-privilege account and isolate it in a segmented network to limit post-exploitation reach.
  • Monitor vendor advisories for a fixed release, since the flaw is related to CVE-2017-17932 and may recur.

Detection

  • Monitor network traffic and firewall logs for inbound connections to TCP port 888 from untrusted sources.
  • Inspect Mediaserver.exe process behavior for crashes, unexpected child processes, or outbound connections after receiving data on port 888.
  • Deploy network IDS signatures for long-string overflow attempts against the ALLMediaServer service on port 888.
  • Search host logs for service restarts or abnormal termination of Mediaserver.exe that correlate with inbound port 888 traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-28381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28480Allmediaserver classic buffer overflow vulnerabilityALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.EPSS 1.8%9.8CVE-2017-17932ALLMediaServer MediaServer.exe buffer overflow via TCP port 888ALLMediaServer 0.95 and earlier ships MediaServer.exe with a buffer overflow reachable by sending a long string to TCP port 888. Because the flaw is …EPSS 54%analysed8.8CVE-2026-86950Apple ipados out-of-bounds write vulnerabilityAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, …KEVEPSS 0.81%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed

Source: NIST National Vulnerability Database (record CVE-2022-28381), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.