CVE-2007-4903
Ultra Crypto Component <= 2.0 - Remote Code Execution via CryptoX.dll ActiveX Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4903. PoCs published by shinnai.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Ultra Crypto Component (CryptoX.dll <= 2.0) via the 'AcquireContext()' method. It uses heap spraying to achieve remote code execution by overwriting memory with shellcode.
Description
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Ultra Crypto Component (CryptoX.dll <= 2.0) via the 'AcquireContext()' method. It uses heap spraying to achieve remote code execution by overwriting memory with shellcode.