CVE-2007-5603
SonicWall SSL-VPN < 2.1 - Stack-Based Buffer Overflow via NetExtender NELaunchCtrl AddRouteEntry Method
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2007-5603.
PoCs published by Metasploit, krafty, MC, including Metasploit module exploits/windows/browser/sonicwall_addrouteentry.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in SonicWall SSL-VPN NetExtender's ActiveX control via the 'AddRouteEntry()' method. It delivers a payload through a malicious HTML page to achieve remote code execution.
Description
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in SonicWall SSL-VPN NetExtender's ActiveX control via the 'AddRouteEntry()' method. It delivers a payload through a malicious HTML page to achieve remote code execution.
This exploit targets a buffer overflow vulnerability in the SonicWall SSL-VPN NeLaunchCtrl ActiveX control. It uses heap spraying and shellcode execution to achieve remote code execution, demonstrated by launching the calculator.
This Metasploit module exploits a stack buffer overflow in SonicWall SSL-VPN NetExtender's ActiveX control via the 'AddRouteEntry()' method. It delivers a crafted payload to achieve remote code execution on vulnerable systems.