CVE-2007-4821
EDraw Office Viewer Component 5.2 - Remote Code Execution via HttpDownloadFileToTempDir Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4821. PoCs published by shinnai.
AI-analyzed exploit summary This is a working proof-of-concept for a remote buffer overflow in EDraw Office Viewer Component 5.2. The exploit leverages the HttpDownloadFileToTempDir method to trigger a SEH-based overflow, potentially leading to remote code execution.
Description
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the HttpDownloadFileToTempDir method, a different vulnerability than CVE-2007-3169.
Exploits (1)
This is a working proof-of-concept for a remote buffer overflow in EDraw Office Viewer Component 5.2. The exploit leverages the HttpDownloadFileToTempDir method to trigger a SEH-based overflow, potentially leading to remote code execution.