CVE-2026-102507 Sliver C2 未处理恐慌漏洞
影响受控植入端可触发服务端崩溃,导致所有操作员断连
Sliver C2 框架 1.7.7 及更早版本的 operator gRPC 处理器存在未捕获的 panic 漏洞。攻击者通过控制被攻陷的植入端(implant)返回畸形或空的 Download 响应,即可使整个 teamserver 进程崩溃。
影响范围
Sliver C2 framework 1.7.7 及更早版本;具体受影响版本范围以官方公告为准。
漏洞详情
漏洞类型为未处理的异常(panic)导致的拒绝服务。成因是 vendored Binject 库的 BinaryMagic 函数在处理零长度或 1~3 字节的短数据负载时发生越界切片访问,异常沿 operator gRPC 拦截器链向上传播且未被恢复,最终终止服务端进程。利用方式为攻击者通过恶意植入端会话发送畸形 Download 响应触发。
利用条件与风险
利用前提是攻击者已控制一个植入端并能与 teamserver 通信;实战中可造成团队服务器整体不可用,影响所有在线操作员,属于中等风险拒绝服务。
修复建议
建议升级至官方修复版本;临时缓解可限制植入端通信权限、对 gRPC 输入做长度校验或增加 panic 恢复机制,具体方案以厂商公告为准。
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads through a hostile implant session to trigger an out-of-bounds slice access in the vendored Binject library’s BinaryMagic function, which propagates unrecovered through the operator gRPC interceptor chain and terminates the server process, affecting all connected operators.