CVE-2017-17099: Flexense Syncbreeze

High severity, CVSS 7.8. EPSS: 11.8% chance of exploitation in the next 30 days.

There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.

Affected products

  • Flexense Syncbreeze: version 10.1.16 only

Published 2017-12-03. Last modified 2026-06-17.