Sceawere

Vulnerability Detail

CVE-2026-102507UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sliver C2 Unhandled Panic Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.7
Creation Date
13h ago
Vendor
BishopFox
Product
sliver
Attack Type
Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.7",
  "pubDate": "2026-09-29T12:17:09.943Z",
  "pubdate": "2026-09-29T12:17:09.943Z",
  "executiveSummary": "Sliver C2 versions 1.7.7 and earlier are susceptible to an unhandled panic vulnerability within the operator gRPC handler, which poses a severe risk to service availability. The vulnerability is classified as an out-of-bounds memory access error, enabling a malicious or compromised implant to trigger a denial-of-service (DoS) condition on the teamserver.\nBy transmitting a specifically crafted, zero-length or malformed 1-3 byte payload to the server, an attacker can force the termination of the teamserver process. Because this panic propagates through the gRPC interceptor chain without proper recovery, the crash impacts all connected operator sessions simultaneously, disrupting C2 infrastructure operations.\nThis vulnerability effectively grants an attacker with control over an implant the ability to perform a remote, unauthenticated crash of the central management server. The exploit requires no complex authentication or high-level permissions on the teamserver; it relies solely on the server's internal processing logic of incoming implant data. The primary risk is the total loss of command and control continuity, potentially impeding incident response and post-exploitation persistence.",
  "technicalDetails": "The vulnerability resides in the interaction between the Sliver teamserver and the third-party 'Binject' library. Specifically, the teamserver utilizes the 'BinaryMagic' function to inspect and process data streams returned by implants during download operations. The vulnerability is rooted in an inadequate validation of input length before accessing slice indices, leading to an out-of-bounds slice access when processing undersized or empty payloads.\nThe attack flow initiates when a compromised implant, directed by an attacker, sends a malicious Download response packet containing zero, one, two, or three bytes of data. When this payload reaches the teamserver, the 'BinaryMagic' function attempts to read indices within the byte array that do not exist for these minimal lengths. In Go, an out-of-bounds slice access triggers a runtime panic.\nCrucially, the architecture of the Sliver gRPC handler fails to implement robust recovery mechanisms (e.g., a deferred 'recover()' block) within the operator gRPC interceptor chain. Consequently, when the 'BinaryMagic' function panics, the exception propagates up the execution stack, unhandled by the gRPC middleware. The Go runtime terminates the entire process immediately upon an unhandled panic to prevent potential memory corruption, resulting in a complete service outage.\nBecause the gRPC handler is intended to facilitate communication between the implant and the operator, this flaw allows for a direct path from the implant's network input to the server's core execution process. The vulnerability is exacerbated by the lack of input sanitization in the handler, allowing the attacker to bypass normal operational flow and trigger the crash at will. The impact is absolute: all active C2 sessions, operator connections, and persistent tasking data associated with the volatile memory of the teamserver become inaccessible until the process is manually or automatically restarted, potentially leading to operational metadata loss or the forfeiture of active engagement nodes."
}
CVE-2026-102507: Sliver C2 Unhandled Panic Vulnerability (MEDIUM Severity, CVSS: 5.7) | Sceawere