muvee Technologies Text-Effect DXT Filter for autoProducer (TextOut.dll v6.0.18.1) Fontsetting property remote buffer overflow exploit
This exploit is for a remote buffer overflow vulnerability found in the muvee Technologies Text-Effect DXT Filter for autoProducer. The vulnerability exists in the Fontsetting property of the TextOut.dll version 6.0.18.1. The bug was discovered by Nine:Situations:Group::Trotzkista and more information can be found on their website at http://retrogod.altervista.org/. The affected software can be downloaded from http://www.muvee.com/en/ and includes muvee AutoProducer 6.0 and 6.1. The exploit has been tested on Windows 2003 Datacenter Edition with Internet Explorer 6 and Windows XP SP2 with Internet Explorer 6. The dll settings for this exploit are as follows: RegKey Safe for Script: False, RegKey Safe for Init: False, Implements IObjectSafety: True, IDisp Safe: Safe for untrusted: caller.