← back
CVE-2018-10299observed exploitation

CVE-2018-10299

45Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 2.8%
from disclosure to weapon18 days
Published on NVDApr 23
1st PoC+18d
VulnCheckApr 23
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.