vendor:
Yahoo! Messenger
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: Yahoo! Messenger
Affected Version From: 8.1.0.249
Affected Version To: 8.1.0.249
Patch Exists: YES
Related CWE: CVE-2007-3147
CPE: a:yahoo:messenger
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP0/SP1 Pro English, Windows 2000 Pro English All
2007
Yahoo! Messenger 8.1.0.249 ActiveX Control Buffer Overflow
This module exploits a stack buffer overflow in the Yahoo! Webcam Upload ActiveX Control (ywcupl.dll) provided by Yahoo! Messenger version 8.1.0.249. By sending a overly long string to the "Server()" method, and then calling the "Send()" method, an attacker may be able to execute arbitrary code. Using the payloads "windows/shell_bind_tcp" and "windows/shell_reverse_tcp" yield for the best results.
Mitigation:
Update to the latest version of Yahoo! Messenger