CVE-2014-6287General(rejetto / http_file_server)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_file_server

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
http_file_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-11: 1Technical Details · 2026-03-11: 103-11
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Aakash Modi@AakashModi1750_
    General

    Completed Steel Mountain on @tryhackme. An 🟢easy🟢 Windows CTF where I enumerated services, exploited Rejetto HFS 2.3 (CVE-2014-6287) for initial access, then used an unquoted service path vulnerability to escalate privileges to Administrator. Room: https://tryhackme.com/room/steelmountain https://t.co/FmnWh1AhzL

    Post summary

    The tweet describes a CTF challenge where the author used the Rejetto HFS 2.3 vulnerability (CVE-2014-6287) for initial access and privilege escalation, but does not provide PoC, active exploitation claims, or patch information.

    0002054
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprejettohttp_file_server---

Explore more