Record summary

CVE-2008-1307 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBKingSoft - 'UpdateOcx2.dll SetUninstallName()' Heap Overflow (PoC)ExploitDB exploitby voidNot analyzed1 file
ExploitDB

PoC details

References

6