Impact
An unhandled panic occurs in the operator gRPC handler of Sliver C2 framework versions 1.7.7 and earlier. The vulnerability stems from an out‑of‑bounds slice access in the vendored Binject library’s BinaryMagic function when processing a malformed or empty Download response. This causes the server process to terminate, disrupting all connected operators, and is mapped to CWE‑125.
Affected Systems
BishopFox Sliver C2 framework version 1.7.7 and earlier
Risk and Exploitability
The vulnerability has a CVSS score of 6.8, is not currently in the CISA KEV catalog, and the EPSS score is not available. Attackers need control of a compromised implant to exploit the flaw by sending zero‑length or 1–3 byte payloads through a hostile implant session, which triggers the out‑of‑bounds access and crashes the server. The risk is moderate, as the DoS impact requires an existing implant compromise. If such a compromise occurs, all operators will be affected until the server is restarted or patched.
OpenCVE Enrichment