CVE-2008-4800
Microsoft Debug Diagnostic Tool - Denial of Service via GetEntryPointForThread Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4800. PoCs published by suN8Hclf.
AI-analyzed exploit summary This exploit triggers a NULL-pointer dereference in the DebugDiag ActiveX control by passing an invalid argument to the GetEntryPointForThread method, causing a denial-of-service condition in Internet Explorer.
Description
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the GetEntryPointForThread method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
Exploits (1)
This exploit triggers a NULL-pointer dereference in the DebugDiag ActiveX control by passing an invalid argument to the GetEntryPointForThread method, causing a denial-of-service condition in Internet Explorer.