CVE-2007-3040
Microsoft Windows 2000 - Stack-Based Buffer Overflow in Agent.Control ActiveX Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3040. PoCs published by Yamata Li.
AI-analyzed exploit summary This exploit leverages a stack-based buffer overflow in Microsoft Agent (agentsvr.exe) via an ActiveX control. The PoC uses JavaScript to trigger the vulnerability by loading a character and executing arbitrary commands, potentially leading to remote code execution.
Description
Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
Exploits (1)
This exploit leverages a stack-based buffer overflow in Microsoft Agent (agentsvr.exe) via an ActiveX control. The PoC uses JavaScript to trigger the vulnerability by loading a character and executing arbitrary commands, potentially leading to remote code execution.