CVE-2010-3275-VLC AMV Dangling Pointer Vulnerability

This module exploits VLC media player when handling a .AMV file. By flipping the 0x41st
byte in the file format (video width/height), VLC crashes due to an invalid pointer, which
allows remote attackers to gain arbitrary code execution

Large Orange VLC media player Traffic Cone Logo

CVE-2010-3275-VLC AMV Dangling Pointer Vulnerability from 4 X Security Team on Vimeo.

CVE-2011-0609 : Adobe Flash Player AVM Bytecode Verification Vulnerability


Vulnerability discovered exploited in the wild This vulnerability was used to attack RSA First information about the 0day published the 2011-03-11 Security Advisory APSA11-01 posted by the vendor the 2011-03-14 First vulnerability analysis provided by villy the 2011-03-15 Metasploit PoC provided by bannedit the 2011-03-22

Affected version(s) :

Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and Solaris Adobe Flash Player 10.2.154.18 and earlier for Chrome users Adobe Flash Player 10.1.106.16 and earlier versions for Android Adobe Reader and Acrobat X (10.0.1) Earlier 10.x and 9.x versions of Reader and Acrobat for Windows and Macintosh

CVE-2011-0609 : Adobe Flash Player AVM Bytecode Verification Vulnerability from 4 X Security Team on Vimeo.




CVE-2010-3747 -RealNetworks RealPlayer CDDA URI Initialization Vulnerability

Vulnerability discovered by CHkr_D591 Vulnerability transmitted to ZDI by CHkr_D591 Vulnerability reported to the vendor by ZDI the 2009-11-24 Coordinated public release of advisory the 2010-10-15 Saint PoC provided the 2010-10-22 Metasploit PoC provided the 2011-03-17

CVE-2010-3747 -RealNetworks RealPlayer CDDA URI Initialization Vulnerability from 4 X Security Team on Vimeo.

Trend Micro Internet Security Pro 2010 ActiveX extSetOwner() Remote Code Execution Exploit

Trend MicroHere’s a Metasploit exploit module I wrote for the Trend Micro Internet Security Pro 2010 ActiveX extSetOwner() remote code execution vulnerability.

This vulnerability was originally discovered by Andrea Micalizzi aka rgod working with Zero Day Initiative. Abysssec Security Team published a binary analysis of this vulnerability as a part of MOAUB.

This module exploits a remote code execution vulnerability in Trend Micro Internet Security Pro 2010 UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll). The extSetOwner() function accepts a parameter and assumes it is an initialized pointer. When sending an invalid pointer to the extSetOwner() function of UfPBCtrl.dll an attacker may be able to execute arbitrary code.

Exploit successfully tested on the following platforms:
– Trend Micro Internet Security Pro 2010 on Internet Explorer 7, Windows XP SP3
– Trend Micro Internet Security Pro 2010 on Internet Explorer 7, Windows Vista SP2


CVE-2010-3189-Trend Micro Internet Security Pro 2010 ActiveX extSetOwner( from 4 X Security Team on Vimeo.

Metasploit_Kingview 6.53 SCADA

This module exploits a buffer overflow in Kingview 6.53. By sending a specially crafted request to port 777 (HistorySvr.exe), a remote attacker may be able to gain arbitrary code execution without authentication.

Metasploit_Kingview 6.53 SCADA from 4xteam on Vimeo.

MS10-002

Executive Summary

This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

ms10_002_aurora from 4xteam on Vimeo.

Microsoft Internet Explorer iepeers.dll use-after-free exploit

New Microsoft Internet Explorer 0day exploit has been found circulating in-the-wild. According to Microsoft, there are targeted attacks attempting to use this vulnerability. Microsoft published a security advisory for this vulnerability here:
Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution

The vulnerability is a use-after-free (invalid pointer reference) vulnerability within iepeers.dll and only Internet Explorer versions 6 and 7 are vulnerable. Internet Explorer 8 and 5 are not affected.

I’ve found this exploit in-the-wild on www.topix21century.com. The payload download and executes a binary file which connects back to notes.topix21century.com.
Here’s the exploit as it was found in-the-wild, a bit un-obfuscated and payload removed – ie_iepeers_wild.txt

And here’s a Metasploit exploit module for this vulnerability. Tested successfully on the following platforms:
– Microsoft Internet Explorer 7, Windows Vista SP2
– Microsoft Internet Explorer 7, Windows XP SP3
– Microsoft Internet Explorer 6, Windows XP SP3

As usual, this post will update with further references and updates when available.
Happy exploitation :-)

ie_iepeers Metasploit from 4xteam on Vimeo.