CVE-2007-5775
CRITICALBitDefender Antivirus Internet Security and Total Security - Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5775.
AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in BitDefender's OScan8.ocx/Oscan81.ocx ActiveX control (CVE-2007-5775). It uses a heap spray technique to achieve arbitrary code execution by corrupting browser memory and launching a calculator as a proof-of-concept payload.
Description
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
Exploits (1)
This exploit targets a memory corruption vulnerability in BitDefender's OScan8.ocx/Oscan81.ocx ActiveX control (CVE-2007-5775). It uses a heap spray technique to achieve arbitrary code execution by corrupting browser memory and launching a calculator as a proof-of-concept payload.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H