vendor:
Visual Basic Enterprise Edition SP6
by:
shinnai
N/A
CVSS
N/A
Buffer Overflow
CWE
Product Name: Visual Basic Enterprise Edition SP6
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Visual Basic Enterprise Edition SP6 vb6skit.dll Buffer Overflow
vb6stkit.dll is a module that contains application programming interface (API) functions that enable Visual Basic applications to create shortcuts (Shell Links) programmatically. In this poc we will create a form containing an overly long string that we pass to the third parameter (lpstrLinkPath) to own EIP. Arbitrary code execution is possible but today I drank a lot of wine therefore I was unable to write an exploit :-D