CVE-2008-4922
DjVu ActiveX Control for Microsoft Office - Buffer Overflow via ImageURL Property
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-4922.
PoCs published by Metasploit, Shahriyar Jalayeri, including Metasploit module exploits/windows/fileformat/djvu_imageurl.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in DjVu ActiveX Component (DjVu_ActiveX_MSOffice.dll 3.0) via an overly long string to the ImageURL() property. It generates an HTML file with embedded JavaScript to trigger the vulnerability and execute arbitrary shellcode.
Description
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.
Exploits (3)
This exploit targets a stack buffer overflow in DjVu ActiveX Component (DjVu_ActiveX_MSOffice.dll 3.0) via an overly long string to the ImageURL() property. It generates an HTML file with embedded JavaScript to trigger the vulnerability and execute arbitrary shellcode.
This exploit targets a buffer overflow vulnerability in DjVu ActiveX Control (DjVu_ActiveX_MSOffice.dll) via the ImageURL property. It combines SEH overwrite and heap spraying techniques to achieve remote code execution by executing a calc.exe payload.
This Metasploit module exploits a stack buffer overflow in DjVu ActiveX Component (DjVu_ActiveX_MSOffice.dll 3.0) via an overly long string to the ImageURL() property, allowing arbitrary code execution. It generates an HTML file with obfuscated JavaScript to trigger the vulnerability.