vendor:
Pegasus ImagN' ActiveX Control
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Pegasus ImagN' ActiveX Control
Affected Version From: 4.00.041
Affected Version To: 4.00.041
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 IT
IE 6 / Pegasus ImagN’ ActiveX Control (IMW32O40.OCX V4.00.041) remote buffer overflow exploit
This exploit targets the Filename property of the Pegasus ImagN' ActiveX Control, causing a remote buffer overflow. The exploit overwrites seh pointers and several vulnerable functions, including BeginReport, CreatePictureExA, DefineImage, DefineImageEx, DefineImageFox, CopyBufToClipExA, LoadEx, and LoadFox. The exploit is designed for Windows XP SP2 IT version using the EIP overwrite method. The author of this exploit is rgod.
Mitigation:
To mitigate this vulnerability, users should update to a patched version of the Pegasus ImagN' ActiveX Control (IMW32O40.OCX).