CVE-2007-3493

NCTAudioStudio <2.7 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3493. PoCs published by shinnai.

AI-analyzed exploit summary This exploit targets an insecure method in NCTAudioStudio2 ActiveX DLL (NCTWavChunksEditor2.dll v. 2.6.1.148) to overwrite the system.ini file via the CreateFile() method. It uses VBScript to trigger the vulnerability in Internet Explorer.

Description

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/4109

This exploit targets an insecure method in NCTAudioStudio2 ActiveX DLL (NCTWavChunksEditor2.dll v. 2.6.1.148) to overwrite the system.ini file via the CreateFile() method. It uses VBScript to trigger the vulnerability in Internet Explorer.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: NCTAudioStudio2 ActiveX DLL (NCTWavChunksEditor2.dll v. 2.6.1.148)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35081
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4109
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37673
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25851
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24656
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2351

Scores

EPSS 0.3131
EPSS Percentile 98.0%

Details

Status published
Products (3)
microsoft/internet_explorer 7.0
nctsoft_products/nctaudiostudio 2.7
nctsoft_products/nctwavchunkseditor2.dll 2.6.1.148
Published Jun 29, 2007
Tracked Since Feb 18, 2026