CVE-2008-2551

EXPLOITED

Icona Instant Messenger 1.0.0.1 - Remote Code Execution via DownloaderActiveX Control

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2008-2551 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including Metasploit, Nine:Situations:Group, Unknown, juan vazquez, including a Metasploit module exploits/windows/browser/c6_messenger_downloaderactivex.

AI-analyzed exploit summary This Metasploit module exploits a vulnerability in Icona SpA C6 Messenger's DownloaderActiveX control to download and execute arbitrary files. It leverages an insecure ActiveX control to achieve remote code execution in the context of the logged-on user.

Description

The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18449

This Metasploit module exploits a vulnerability in Icona SpA C6 Messenger's DownloaderActiveX control to download and execute arbitrary files. It leverages an insecure ActiveX control to achieve remote code execution in the context of the logged-on user.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Icona SpA C6 Messenger 1.0.0.1
No auth needed
Prerequisites: Target must be using Internet Explorer with the vulnerable ActiveX control installed · Target must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Nine:Situations:Group · htmlremotewindows
https://www.exploit-db.com/exploits/5732

This exploit leverages an unsafe ActiveX control in C6 Messenger to remotely download and execute arbitrary files. The vulnerability arises from improper validation of the 'propDownloadUrl' and 'propPostDownloadAction' parameters, allowing remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: C6 Messenger (DownloaderActiveX Control)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer · C6 Messenger DownloaderActiveX control must be installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Unknown, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/c6_messenger_downloaderactivex.rb

This Metasploit module exploits a vulnerability in the Icona SpA C6 Messenger DownloaderActiveX control to download and execute arbitrary files. It leverages an insecure ActiveX control to achieve remote code execution by crafting a malicious HTML page that triggers the download and execution of a payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Icona SpA C6 Messenger 1.0.0.1
No auth needed
Prerequisites: Target must be using Internet Explorer with the vulnerable ActiveX control installed · Target must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1733/references
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3926
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30512
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29519
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493019/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42825
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5732

Scores

EPSS 0.8510
EPSS Percentile 99.4%

Details

VulnCheck KEV 2021-08-17
CWE
CWE-264
Status published
Products (1)
icona/instant_messenger 1.0.0.1
Published Jun 04, 2008
Tracked Since Feb 18, 2026