VendorsMetasploitmetasploit_frameworkall versions
Vulnerabilities

Metasploit Metasploit Framework

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2011-1056
The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.
Published 2011-02-21 · Modified
6.2EPSS 0.003
CVE-2005-2482
The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.
Published 2005-08-07 · Modified
5.0EPSS 0.012