vendor:
N/A
by:
牛奶坦克
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Exploit-DB Notes
This exploit is a buffer overflow vulnerability in the AddContextRef() method of the ActiveX control with CLSID 2745E5F5-D234-11D0-847A-00C04FD7BB08. The exploit uses a shellcode to run calc.exe. The exploit first creates a big block of memory and then fills it with the shellcode. It then creates an array of 350 elements, each element containing the block of memory with the shellcode. Finally, it calls the AddContextRef() method with the address 0x0c0c0c0c, which is the address of the first element of the array.
Mitigation:
Disable the ActiveX control with CLSID 2745E5F5-D234-11D0-847A-00C04FD7BB08.