Description
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.
Published: 2026-09-29
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service to the entire teamserver
Action: Patch
AI Analysis

Impact

An unhandled panic occurs in the operator gRPC handler of Sliver C2 framework versions 1.7.7 and earlier. The vulnerability stems from an out‑of‑bounds slice access in the vendored Binject library’s BinaryMagic function when processing a malformed or empty Download response. This causes the server process to terminate, disrupting all connected operators, and is mapped to CWE‑125.

Affected Systems

BishopFox Sliver C2 framework version 1.7.7 and earlier

Risk and Exploitability

The vulnerability has a CVSS score of 6.8, is not currently in the CISA KEV catalog, and the EPSS score is not available. Attackers need control of a compromised implant to exploit the flaw by sending zero‑length or 1–3 byte payloads through a hostile implant session, which triggers the out‑of‑bounds access and crashes the server. The risk is moderate, as the DoS impact requires an existing implant compromise. If such a compromise occurs, all operators will be affected until the server is restarted or patched.

Generated by OpenCVE AI on September 29, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Sliver release that fixes the Binject plugin issue and removes the out‑of‑bounds error.
  • Restart the Sliver teamserver after applying the patch to recover from any crash state.
  • Restrict access to the vulnerable RPC endpoint or block malicious payloads by configuring firewall or limits until the patch is applied.

Generated by OpenCVE AI on September 29, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Bishopfox
Bishopfox sliver
Vendors & Products Bishopfox
Bishopfox sliver

Tue, 29 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library's BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.
Title Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bishopfox Sliver
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-29T17:56:57.805Z

Reserved: 2026-09-29T11:37:09.721Z

Link: CVE-2026-102507

cve-icon Vulnrichment

Updated: 2026-09-29T17:56:53.654Z

cve-icon NVD

Status : Received

Published: 2026-09-29T12:17:09.943

Modified: 2026-09-29T18:17:07.853

Link: CVE-2026-102507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T18:45:10Z

Weaknesses