PatchSiren cyber security CVE debrief
CVE-2017-5229 Rapid7 CVE debrief
CVE-2017-5229 is a high-severity directory traversal issue in Rapid7 Metasploit’s Meterpreter extapi Clipboard.parse_dump() path handling. A specially crafted Meterpreter build could cause the Metasploit console to write into an arbitrary directory with the privileges of the running instance. The vulnerability was published on 2017-03-02; NVD later updated the record on 2026-05-13.
- Vendor
- Rapid7
- Product
- Metasploit
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Teams running Metasploit consoles, red-team infrastructure, shared lab systems, or any environment where Meterpreter payloads may be processed by a long-lived Metasploit instance. Console operators should care because the flaw can affect the host filesystem, not just the Meterpreter session.
Technical summary
The issue is a directory traversal vulnerability affecting the Meterpreter extapi Clipboard.parse_dump() function. According to the CVE description, a specially crafted Meterpreter build can direct writes outside the intended path and place data in an arbitrary directory on the Metasploit console host, limited by the permissions of the Metasploit process. NVD classifies the weakness as CWE-22 and rates the issue CVSS 3.0 7.1 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L). The supplied sources indicate affected Metasploit versions prior to the vendor-fixed build referenced in the advisory, while NVD’s current CPE range maps vulnerability through 4.13.19.
Defensive priority
High. This is not a remote code execution claim, but it can still affect integrity and confidentiality on the console host. Prioritize if you run exposed, shared, or automation-driven Metasploit infrastructure that ingests Meterpreter artifacts.
Recommended defensive actions
- Upgrade Rapid7 Metasploit to the fixed release referenced in the vendor advisory and ensure all console hosts are on a patched build.
- Restrict which Meterpreter payloads and artifacts are accepted by operational tooling; treat unexpected or externally supplied builds as untrusted input.
- Run Metasploit consoles with the least-privilege account possible and isolate them from sensitive filesystem locations.
- Review filesystem permissions and monitoring around the Metasploit working directories to detect unexpected writes outside expected paths.
- If you cannot patch immediately, limit access to the console host and reduce exposure to untrusted sessions or payload handling workflows.
Evidence notes
Primary evidence comes from the CVE record and NVD entry. The CVE description states all editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in Meterpreter extapi Clipboard.parse_dump(). NVD classifies it as CWE-22 and lists a vulnerable cpe range ending at 4.13.19. The vendor advisory link in the supplied sources provides the mitigation context, while the CVE record and NVD detail page are the authoritative references used here.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5229 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5229
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5229 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5229
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://community.rapid7.com/community/infosec/blog/2017/03/01/multiple-vulnerabilities-affecting-four-rapid7-products
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.