CVE-2007-2888

UltraISO <8.6.2.2011 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16627
exploitdb WORKING POC VERIFIED
by Thomas Pollet · pythonlocalwindows
https://www.exploit-db.com/exploits/4002
exploitdb WORKING POC VERIFIED
by n00b · c++localwindows
https://www.exploit-db.com/exploits/4001
exploitdb WORKING POC VERIFIED
by n00b · perldoswindows
https://www.exploit-db.com/exploits/3978
metasploit WORKING POC GREAT
by n00b, jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ultraiso_cue.rb

Scores

EPSS 0.8148
EPSS Percentile 99.2%

Details

Status published
Products (1)
ezb_systems/ultraiso < 8.6.2.2011
Published May 30, 2007
Tracked Since Feb 18, 2026