vendor:
NCTAudioFile2.AudioFile
by:
InTeL
7.5
CVSS
HIGH
Stack Overflow
Buffer Overflow
CWE
Product Name: NCTAudioFile2.AudioFile
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not specified
CPE: Not specified
Platforms Tested: Windows 2000 SP4 with Internet Explorer 6, Windows XP Professional SP2 with Internet Explorer 7
Unknown
[PoC] 79 Exes’s / IE NCTAudioFile2.AudioFile ActiveX Remote Stack Overfl0w
This exploit takes advantage of a stack overflow vulnerability in the NCTAudioFile2.AudioFile ActiveX component in Internet Explorer. By visiting a malicious webpage, an attacker can trigger the stack overflow and execute arbitrary code.
Mitigation:
Disable the NCTAudioFile2.AudioFile ActiveX component or use a different web browser.