CVE-2008-1602

Orbit Downloader <2.6.4 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-1602. PoCs published by Metasploit, Diego Juarez, juan vazquez, including Metasploit module exploits/windows/fileformat/orbit_download_failed_bof.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in Orbit Downloader via a crafted metalink file. It leverages the MultiByteToWideChar function to trigger the vulnerability, leading to arbitrary code execution.

Description

Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/18515

This exploit targets a stack-based buffer overflow in Orbit Downloader via a crafted metalink file. It leverages the MultiByteToWideChar function to trigger the vulnerability, leading to arbitrary code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Orbit Downloader 6.4
No auth needed
Prerequisites: Victim must open the malicious metalink file in Orbit Downloader
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Diego Juarez, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/orbit_download_failed_bof.rb

This exploit leverages a stack-based buffer overflow in Orbit Downloader via a maliciously crafted metalink file. The vulnerability arises from insecure Unicode conversion using MultiByteToWideChar, allowing arbitrary code execution when the file is opened.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Orbit Downloader 6.4
No auth needed
Prerequisites: Victim must open the crafted metalink file in Orbit Downloader
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3798
Exploit, Patch x_refsource_misc
http://www.coresecurity.com/?action=item&id=2211
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1101
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/490458/100/0/threaded
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28541
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29669
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41649

Scores

EPSS 0.6749
EPSS Percentile 99.2%

Details

CWE
CWE-119
Status published
Products (2)
orbit_downloader/orbit_downloader 2.6.3
orbit_downloader/orbit_downloader 2.6.4
Published Apr 06, 2008
Tracked Since Feb 18, 2026