CVE-2007-2576

East Wind Software advdaudio.ocx <1.5.1.1 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2576. PoCs published by shinnai.

AI-analyzed exploit summary This exploit targets a local buffer overflow in East Wind Software's advdaudio.ocx (v. 1.5.1.1) via the 'OpenDVD' method. It uses a crafted buffer with shellcode to achieve arbitrary code execution when triggered via VBScript in Internet Explorer.

Description

Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to execute arbitrary code via a long OpenDVD property value. NOTE: this issue might be related to CVE-2007-0976.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmllocalwindows
https://www.exploit-db.com/exploits/3856

This exploit targets a local buffer overflow in East Wind Software's advdaudio.ocx (v. 1.5.1.1) via the 'OpenDVD' method. It uses a crafted buffer with shellcode to achieve arbitrary code execution when triggered via VBScript in Internet Explorer.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: East Wind Software advdaudio.ocx v. 1.5.1.1
No auth needed
Prerequisites: Victim must open the malicious HTML file in Internet Explorer · advdaudio.ocx must be installed and registered
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_misc
http://moaxb.blogspot.com/2007_05_05_archive.html
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3856
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34119
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23833
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34337

Scores

EPSS 0.0487
EPSS Percentile 90.9%

Details

Status published
Products (1)
east_wind_software/advdaudio.ocx 1.5.1.1
Published May 09, 2007
Tracked Since Feb 18, 2026