Vulnerability record · CVE-2022-28381 · published 3 April 2022
CVE-2022-28381: ALLMediaServer Mediaserver.exe stack buffer overflow via TCP port 888
Allmediaserver · Allmediaserver
ALLMediaServer 1.6 contains a stack-based buffer overflow in Mediaserver.exe reachable over TCP port 888, where a long string overwrites stack memory. It is a related issue to CVE-2017-17932, indicating the same class of flaw was not fully fixed. Successful exploitation allows remote code execution on the host running the media server.
Description
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit code plus very high EPSS make this an urgent exposure for any host running ALLMediaServer 1.6.
What it is
ALLMediaServer 1.6 contains a stack-based buffer overflow in Mediaserver.exe reachable over TCP port 888, where a long string overwrites stack memory. It is a related issue to CVE-2017-17932, indicating the same class of flaw was not fully fixed. Successful exploitation allows remote code execution on the host running the media server.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the Mediaserver.exe process, giving full control of that service and potentially the underlying host. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network via TCP port 888 with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any host exposing the ALLMediaServer service on that port is directly exposed.
Exploitation
Public exploit code is referenced in Packet Storm and a GitHub repository, and EPSS is 0.70405 (99.355th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded there.
What to do
- Upgrade ALLMediaServer to a version later than 1.6 if the vendor has released a fix; the record does not name a patched version, so confirm with the vendor.
- If no patch exists, remove or disable the ALLMediaServer service on any internet-facing or untrusted network segment.
- Block or restrict inbound TCP port 888 to trusted hosts only, and place the service behind a firewall or VPN.
- Run the service under a low-privilege account and isolate it in a segmented network to limit post-exploitation reach.
- Monitor vendor advisories for a fixed release, since the flaw is related to CVE-2017-17932 and may recur.
Detection
- Monitor network traffic and firewall logs for inbound connections to TCP port 888 from untrusted sources.
- Inspect Mediaserver.exe process behavior for crashes, unexpected child processes, or outbound connections after receiving data on port 888.
- Deploy network IDS signatures for long-string overflow attempts against the ALLMediaServer service on port 888.
- Search host logs for service restarts or abnormal termination of Mediaserver.exe that correlate with inbound port 888 traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166573/ALLMediaServer-1.6-Buffer-Overflow.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Matrix07ksa/ALLMediaServer-1.6-Buffer-Overflow | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/166573/ALLMediaServer-1.6-Buffer-Overflow.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Matrix07ksa/ALLMediaServer-1.6-Buffer-Overflow | ExploitThird Party Advisory |
Track CVE-2022-28381 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-28381), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.