CVE-2007-0015
EXPLOITEDApple QuickTime 7.1.3 - Remote Code Execution via Long RTSP URI
Title source: llmExploitation Summary
CVE-2007-0015 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 4 public exploits from researchers including Metasploit, Winny Thomas, MoAB, including a Metasploit module exploits/windows/browser/apple_quicktime_rtsp.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in Apple QuickTime 7.1.3 via a maliciously crafted RTSP URI. It supports both direct QuickTime Player exploitation and browser-based attacks using heap spraying.
Description
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
Exploits (4)
This Metasploit module exploits a buffer overflow in Apple QuickTime 7.1.3 via a maliciously crafted RTSP URI. It supports both direct QuickTime Player exploitation and browser-based attacks using heap spraying.
This exploit generates a malicious QTL file targeting CVE-2007-0015 in Apple QuickTime RTSP, binding a shell to port 4444. It uses alphanumeric shellcode and a JMP EDI address from user32.dll for Windows 2000 SP0/SP4.
This exploit targets a buffer overflow vulnerability in QuickTime for Mac OS X 10.4.8 by crafting a malicious QTL file. It leverages static addresses for system() and setuid() to execute arbitrary commands, with a payload designed to trigger the vulnerability via a malformed RTSP URL.
This Metasploit module exploits a buffer overflow in Apple QuickTime 7.1.3 via a maliciously crafted RTSP URI in a QTL file. It supports both direct QuickTime player exploitation and browser-based attacks using heap spraying.