CVE-2007-5755

AOL Radio AmpX ActiveX Control - Remote Code Execution via Stack-Based Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5755. Includes Metasploit module exploits/windows/browser/aol_ampx_convertfile.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in the AOL Radio AmpX ActiveX control (AmpX.dll v2.4.0.6) via an overly long value passed to the ConvertFile() method, leading to arbitrary code execution.

Description

Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary code via long arguments to unspecified methods.

Exploits (1)

metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/aol_ampx_convertfile.rb

This Metasploit module exploits a stack-based buffer overflow in the AOL Radio AmpX ActiveX control (AmpX.dll v2.4.0.6) via an overly long value passed to the ConvertFile() method, leading to arbitrary code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: AOL Radio AmpX ActiveX Control (AmpX.dll) version 2.4.0.6
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · AOL Radio AmpX ActiveX control must be installed
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (7)

Core 7
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26396
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27622
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38705
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=623
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018929
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38397
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3822

Scores

EPSS 0.1297
EPSS Percentile 95.8%

Details

CWE
CWE-119
Status published
Products (1)
aol/radio
Published Nov 14, 2007
Tracked Since Feb 18, 2026