CVE-2007-2666
Notepad++ < 4.1.1 - Stack-based Buffer Overflow in LexRuby.cxx
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2666. PoCs published by vade79.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Notepad++ v4.1 when processing Ruby files (.rb). It overwrites EAX and EIP to redirect execution to a NOP sled and shellcode, spawning calc.exe by default.
Description
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Notepad++ v4.1 when processing Ruby files (.rb). It overwrites EAX and EIP to redirect execution to a NOP sled and shellcode, spawning calc.exe by default.