CVE-2007-2888
UltraISO <8.6.2.2011 - Buffer Overflow
Title source: llmDescription
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16627
exploitdb
WORKING POC
VERIFIED
by Thomas Pollet · pythonlocalwindows
https://www.exploit-db.com/exploits/4002
metasploit
WORKING POC
GREAT
by n00b, jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ultraiso_cue.rb
References (5)
Scores
EPSS
0.8148
EPSS Percentile
99.2%
Details
Status
published
Products (1)
ezb_systems/ultraiso
< 8.6.2.2011
Published
May 30, 2007
Tracked Since
Feb 18, 2026