CVE-2007-2856

Dart Communications PowerTCP ZIP Compression ActiveX - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-2856. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Dart Communications PowerTCP ZIP Compression Control (DartZip.dll 1.8.5.3) via Internet Explorer 6. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode that adds a user to the system.

Description

Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.

Exploits (2)

exploitdb WORKING POC VERIFIED
by rgod · htmlremotewindows
https://www.exploit-db.com/exploits/3984

This exploit targets a buffer overflow vulnerability in Dart Communications PowerTCP ZIP Compression Control (DartZip.dll 1.8.5.3) via Internet Explorer 6. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode that adds a user to the system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Dart Communications PowerTCP ZIP Compression Control (DartZip.dll 1.8.5.3)
No auth needed
Prerequisites: Internet Explorer 6 · DartZip.dll 1.8.5.3 installed · User interaction to open the malicious HTML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by rgod · htmlremotewindows
https://www.exploit-db.com/exploits/3982

This exploit targets a buffer overflow vulnerability in Dart Communications PowerTCP Service Control (DartService.dll 3.1.3.3) via Internet Explorer 6. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode, adding a new administrator user.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Dart Communications PowerTCP Service Control (DartService.dll 3.1.3.3)
No auth needed
Prerequisites: Internet Explorer 6 · Dart Communications PowerTCP Service Control (DartService.dll 3.1.3.3) installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24163
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/469592/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38111
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34494
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/469503/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34520
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24142

Scores

EPSS 0.0717
EPSS Percentile 93.5%

Details

CWE
CWE-119
Status published
Products (1)
dart/powertcp_zip_compression 1.8.5.3
Published May 24, 2007
Tracked Since Feb 18, 2026