<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MOOS - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/moos/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 23:29:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/moos/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Overflow Vulnerability in MOOS ui-moos</title><link>https://feed.craftedsignal.io/briefs/2026-09-03-moos-buffer-overflow/</link><pubDate>Thu, 03 Sep 2026 23:29:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-03-moos-buffer-overflow/</guid><description>The ui-moos component is vulnerable to a buffer overflow in ScopeTabPane.cpp and ScopeGrid.cpp, potentially allowing arbitrary code execution when processing crafted MOOS identifiers.</description><content:encoded><![CDATA[<p>The MOOS (Mission Oriented Operating Suite) ui-moos component, specifically versions through commit 50b9c6c, contains a critical buffer overflow vulnerability within ScopeTabPane.cpp and ScopeGrid.cpp. The vulnerability arises from the use of the sprintf function to format client and variable names into fixed 1024-byte buffers without appropriate length validation. An attacker capable of interacting with the application can supply arbitrarily long MOOS identifiers. When an operator performs actions such as selecting entries from the process list or poking variables, the application attempts to write these overly large strings into the insufficient buffers, triggering a memory corruption event. This vulnerability poses a significant risk to the integrity and availability of the MOOS environment, as successful exploitation could lead to arbitrary code execution on systems running the affected ui-moos component.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-85452 allows an attacker to achieve code execution within the context of the user running the ui-moos application. This could result in unauthorized system access, data exfiltration, or total compromise of the affected workstation. Given that MOOS is typically used in robotics, marine, and autonomous systems, the operational impact of such a compromise could involve the loss of control over autonomous vehicles or failure of critical mission software.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating the ui-moos component to a version beyond commit 50b9c6c. Since no official patch release version is specified, verify the fix via source code analysis of the commit history to ensure the sprintf usage has been replaced with safer functions like snprintf. In environments where immediate patching is not possible, implement network segmentation and strict access controls to limit the ability of unauthorized entities to send MOOS identifier packets or interact with the ui-moos process list features.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>buffer-overflow</category></item><item><title>Remote Code Execution in MOOS essential-moos pAntler</title><link>https://feed.craftedsignal.io/briefs/2026-09-moos-pantler-rce/</link><pubDate>Thu, 03 Sep 2026 23:25:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-moos-pantler-rce/</guid><description>The pAntler component in essential-moos versions 10.0.1 and earlier allows unauthenticated attackers to achieve remote code execution by publishing a crafted MISSION_FILE message to the MOOSDB.</description><content:encoded><![CDATA[<p>The MOOS-IvP open-source project essential-moos suite, specifically the pAntler component through version 10.0.1, contains a critical remote code execution vulnerability. pAntler is designed to manage and launch various MOOS processes defined within a mission file. An unauthenticated attacker capable of communicating with the MOOSDB can publish a specially crafted 'MISSION_FILE' message. The pAntler application reads the contents of this message and parses it for 'Run' entries. Due to a lack of authentication and input validation on these entries, pAntler passes the user-supplied strings directly to the execvp() system call, resulting in the execution of arbitrary programs with the privileges of the pAntler process. This vulnerability is significant for autonomous systems and research platforms that utilize the MOOS-IvP architecture, as it allows for full command execution on the host machine.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes network connectivity to the target MOOSDB port.</li>
<li>Attacker crafts a malicious MISSION_FILE message containing arbitrary commands within 'Run' entries.</li>
<li>Attacker publishes the crafted message to the MOOSDB via the MOOS protocol.</li>
<li>The pAntler component receives the malicious MISSION_FILE message from the MOOSDB.</li>
<li>pAntler parses the 'Run' entries within the message without validating the input.</li>
<li>pAntler calls the execvp() system call, passing the malicious entries.</li>
<li>The operating system executes the attacker-defined program on the host.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to execute arbitrary programs on systems running affected versions of essential-moos. This can lead to full system compromise, loss of control over autonomous mission software, and data exfiltration. The vulnerability affects research and robotics environments utilizing the MOOS-IvP middleware.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the essential-moos software to a version beyond 10.0.1 immediately, if available, or isolate MOOSDB instances from untrusted network segments.</li>
<li>Implement network access controls (NAC) to restrict communication with the MOOSDB port to authorized and authenticated mission components only.</li>
<li>Audit environments for the use of pAntler and ensure process execution policies are configured to minimize the impact of unauthorized sub-process spawning.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>vulnerability</category><category>cve</category><category>network-security</category></item><item><title>CVE-2026-85440: Heap Overflow in MOOS core-moos</title><link>https://feed.craftedsignal.io/briefs/2026-09-moos-heap-overflow/</link><pubDate>Thu, 03 Sep 2026 23:25:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-moos-heap-overflow/</guid><description>A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.</description><content:encoded><![CDATA[<p>MOOS core-moos versions up to 10.4.0 contain a critical heap-based buffer overflow vulnerability within the MOOSCommPkt packet handling logic. The issue resides in the HandShake phase, which occurs before authentication is established. An unauthenticated remote attacker can supply a negative value in the packet length field, which bypasses existing signed integer checks within the InflateTo() function. This discrepancy leads to an improper size conversion when the data is passed to the recv() function, causing a heap overflow of a four-byte buffer. Successful exploitation allows an attacker to write arbitrary data into the process memory, potentially leading to remote code execution or application crashes. Given the pre-authentication nature of this flaw, defenders should prioritize patching or restricting access to the MOOS communication ports.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes a TCP/IP connection to the target host on the MOOS communication port.</li>
<li>Attacker initiates the HandShake phase of the communication protocol.</li>
<li>Attacker crafts a malicious packet header containing a negative integer in the packet length field.</li>
<li>The victim application receives the malicious packet via the InflateTo() function.</li>
<li>The vulnerability in the signed integer check allows the negative length to pass validation.</li>
<li>The application performs a heap-based memory allocation based on the unchecked length.</li>
<li>The recv() function processes the attacker-supplied data, resulting in a heap overflow of the internal four-byte buffer.</li>
<li>Attacker achieves arbitrary memory write, leading to remote code execution or process termination.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause a denial-of-service condition on affected MOOS installations. This affects systems utilizing MOOS core-moos versions 10.4.0 and earlier. Organizations relying on this software for underwater vehicle communication or similar robotics research environments are at high risk if instances are exposed to untrusted networks.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions:</p>
<ul>
<li>Patch core-moos by upgrading to a version exceeding 10.4.0 immediately upon release of vendor updates.</li>
<li>Until patching is possible, restrict access to MOOS communication ports via host-based firewalls or network access control lists to known trusted endpoints only.</li>
<li>Monitor network traffic for anomalous packet headers directed toward MOOS services, specifically looking for TCP streams containing negative length identifiers in the handshake phase.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve</category><category>authentication-bypass</category><category>middleware</category><category>denial-of-service</category><category>network-vulnerability</category><category>vulnerability</category><category>network-security</category><category>remote-access</category></item></channel></rss>