CVE-2007-4336

Microsoft DirectX Media 6.0 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4336. PoCs published by h07.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the Microsoft DXMedia SDK 6 ActiveX control via the 'SourceUrl' property. It uses heap spraying to achieve remote code execution by overwriting memory with shellcode that launches calc.exe.

Description

Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a long SourceUrl property value.

Exploits (1)

exploitdb WORKING POC VERIFIED
by h07 · htmlremotewindows
https://www.exploit-db.com/exploits/4279

This exploit targets a buffer overflow vulnerability in the Microsoft DXMedia SDK 6 ActiveX control via the 'SourceUrl' property. It uses heap spraying to achieve remote code execution by overwriting memory with shellcode that launches calc.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft DXMedia SDK 6.0
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 6 · Microsoft DXMedia SDK 6.0 ActiveX control must be installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35970
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25279
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018551
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4279
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2857
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/466601
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26426
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36399

Scores

EPSS 0.5071
EPSS Percentile 98.8%

Details

Status published
Products (1)
microsoft/directx_media 6.0
Published Aug 14, 2007
Tracked Since Feb 18, 2026