CVE-2008-3008
EXPLOITEDWindows Media Encoder - Stack-based Buffer Overflow via GetDetailsString Method
Title source: llmExploitation Summary
CVE-2008-3008 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 3 public exploits from researchers including Metasploit, haluznik, MC, including a Metasploit module exploits/windows/browser/ms08_053_mediaencoder.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in Windows Media Encoder 9 via the GetDetailsString() method of wmex.dll. It uses a Metasploit module to deliver a payload through a malicious HTML page with embedded JavaScript.
Description
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability."
Exploits (3)
This exploit targets a stack buffer overflow in Windows Media Encoder 9 via the GetDetailsString() method of wmex.dll. It uses a Metasploit module to deliver a payload through a malicious HTML page with embedded JavaScript.
This exploit targets a buffer overflow vulnerability in the Windows Media Encoder wmex.dll ActiveX control (CVE-2008-3008). It uses a crafted HTML page with JavaScript to trigger the overflow and execute arbitrary shellcode, leading to remote code execution.
This Metasploit module exploits a stack buffer overflow in Windows Media Encoder 9 via the GetDetailsString() method of wmex.dll. It delivers a payload through a malicious HTML page with embedded JavaScript to achieve remote code execution.