Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-1867. PoCs published by Breno Silva Pinto, Marsu.
AI-analyzed exploit summary This exploit generates a malicious .ANI file targeting a buffer overflow in IrfanView 3.99, delivering a port bind shellcode (port 4444) for multiple Windows XP SP2 targets. It overwrites the return address with a CALL ESP instruction from kernel32.dll.
Description
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
Exploits (2)
This exploit generates a malicious .ANI file targeting a buffer overflow in IrfanView 3.99, delivering a port bind shellcode (port 4444) for multiple Windows XP SP2 targets. It overwrites the return address with a CALL ESP instruction from kernel32.dll.
This exploit targets a buffer overflow vulnerability in IrfanView 3.99 when processing crafted .ANI files. It constructs a malicious .ANI file with embedded shellcode to launch calc.exe via a CALL ESP instruction in Kernel32.dll.