CVE-2008-0399

Toshiba Surveillix - Remote Code Execution via Long Arguments to SetPort or SetIpAddress Methods

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0399. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Toshiba Surveillance (Surveillix) RecordSend Class (MeIpCamX.DLL 1.0.0.4) via a maliciously crafted HTML page. It uses a heap spray technique to achieve remote code execution on Internet Explorer 7 with Windows XP SP2.

Description

Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · htmlremotewindows
https://www.exploit-db.com/exploits/4946

This exploit targets a buffer overflow vulnerability in Toshiba Surveillance (Surveillix) RecordSend Class (MeIpCamX.DLL 1.0.0.4) via a maliciously crafted HTML page. It uses a heap spray technique to achieve remote code execution on Internet Explorer 7 with Windows XP SP2.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Toshiba Surveillance (Surveillix) MeIpCamX.DLL 1.0.0.4
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 7 on Windows XP SP2 · MeIpCamX.DLL 1.0.0.4 must be installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39792
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4946
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28557
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27360
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0214

Scores

EPSS 0.0798
EPSS Percentile 94.0%

Details

CWE
CWE-119
Status published
Products (1)
toshiba/surveillix 1.0.0.4
Published Jan 23, 2008
Tracked Since Feb 18, 2026