CVE-1999-1484
MSN Setup Bulletin Board Services 4.71.0.10 - Remote Code Execution via ActiveX Control Methods
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-1999-1484. PoCs published by Shane Hird.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow in the MSN Setup BBS ActiveX control (setupbbs.ocx) via the vAddNewsServer or bIsNewsServerConfigured methods, allowing arbitrary command execution. The PoC uses a long string to overwrite the return address, targeting ExitProcess for a clean exit.
Description
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.
Exploits (1)
This exploit demonstrates a buffer overflow in the MSN Setup BBS ActiveX control (setupbbs.ocx) via the vAddNewsServer or bIsNewsServerConfigured methods, allowing arbitrary command execution. The PoC uses a long string to overwrite the return address, targeting ExitProcess for a clean exit.