CVE-2006-6410
VMware Workstation - Buffer Overflow via ActiveX Control Initialize Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6410. PoCs published by c0ntex.
AI-analyzed exploit summary This exploit targets a local buffer overflow in VMWare ActiveX component (CVE-2006-6410) by leveraging a heap spray technique to execute arbitrary shellcode (calc.exe) on Windows XP SP2. The exploit uses a combination of JavaScript and VBScript to trigger the vulnerability.
Description
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.
Exploits (1)
This exploit targets a local buffer overflow in VMWare ActiveX component (CVE-2006-6410) by leveraging a heap spray technique to execute arbitrary shellcode (calc.exe) on Windows XP SP2. The exploit uses a combination of JavaScript and VBScript to trigger the vulnerability.