This module exploits VLC media player when handling a .AMV file. By flipping the 0x41st byte in the file format (video width/height), VLC crashes due to an invalid pointer, which allows remote attackers to gain arbitrary code execution
Vulnerability discovered exploited in the wild This vulnerability was used to attack RSA First information about the 0day published the 2011-03-11 Security Advisory APSA11-01 posted by the vendor the 2011-03-14 First vulnerability analysis provided by villy the 2011-03-15 Metasploit PoC provided by bannedit the 2011-03-22
Affected version(s) :
Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and Solaris Adobe Flash Player 10.2.154.18 and earlier for Chrome users Adobe Flash Player 10.1.106.16 and earlier versions for Android Adobe Reader and Acrobat X (10.0.1) Earlier 10.x and 9.x versions of Reader and Acrobat for Windows and Macintosh
Vulnerability discovered by CHkr_D591 Vulnerability transmitted to ZDI by CHkr_D591 Vulnerability reported to the vendor by ZDI the 2009-11-24 Coordinated public release of advisory the 2010-10-15 Saint PoC provided the 2010-10-22 Metasploit PoC provided the 2011-03-17
Trend MicroHere’s a Metasploit exploit module I wrote for the Trend Micro Internet Security Pro 2010 ActiveX extSetOwner() remote code execution vulnerability.
This vulnerability was originally discovered by Andrea Micalizzi aka rgod working with Zero Day Initiative. Abysssec Security Team published a binary analysis of this vulnerability as a part of MOAUB.
This module exploits a remote code execution vulnerability in Trend Micro Internet Security Pro 2010 UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll). The extSetOwner() function accepts a parameter and assumes it is an initialized pointer. When sending an invalid pointer to the extSetOwner() function of UfPBCtrl.dll an attacker may be able to execute arbitrary code.
Exploit successfully tested on the following platforms: – Trend Micro Internet Security Pro 2010 on Internet Explorer 7, Windows XP SP3 – Trend Micro Internet Security Pro 2010 on Internet Explorer 7, Windows Vista SP2
This module exploits a buffer overflow in Kingview 6.53. By sending a specially crafted request to port 777 (HistorySvr.exe), a remote attacker may be able to gain arbitrary code execution without authentication.
This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
New Microsoft Internet Explorer 0day exploit has been found circulating in-the-wild. According to Microsoft, there are targeted attacks attempting to use this vulnerability. Microsoft published a security advisory for this vulnerability here: Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution
The vulnerability is a use-after-free (invalid pointer reference) vulnerability within iepeers.dll and only Internet Explorer versions 6 and 7 are vulnerable. Internet Explorer 8 and 5 are not affected.
I’ve found this exploit in-the-wild on www.topix21century.com. The payload download and executes a binary file which connects back to notes.topix21century.com. Here’s the exploit as it was found in-the-wild, a bit un-obfuscated and payload removed – ie_iepeers_wild.txt
And here’s a Metasploit exploit module for this vulnerability. Tested successfully on the following platforms: – Microsoft Internet Explorer 7, Windows Vista SP2 – Microsoft Internet Explorer 7, Windows XP SP3 – Microsoft Internet Explorer 6, Windows XP SP3
As usual, this post will update with further references and updates when available. Happy exploitation :-)