Executive brief
Gladinet Triofox Server Agent is a software component used to synchronize and manage files between local servers and cloud storage. A critical security flaw allows an unauthenticated attacker to send a specially crafted web request to the server, potentially leading to a complete system takeover or service disruption. This could result in unauthorized access to sensitive corporate data or the ability to execute malicious code on the host server.
Technical details
A stack-based buffer overflow vulnerability exists in the WOSDefaultHttpModule.dll component of Gladinet Triofox Server Agent. The flaw is triggered when the GladServerAgentService.exe, which listens on TCP port 7878, processes a maliciously crafted, overly long URL path starting with the /woshome prefix. An unauthenticated remote attacker can exploit this to overwrite stack memory, potentially leading to arbitrary code execution with the privileges of the service. The vulnerability was identified in version 17.1.10488.57063.
Affected products
- Gladinet Triofox Server Agent 17.1.10488.57063
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory