Exploitation Summary
EIP tracks 4 public exploits for CVE-2009-0450. PoCs published by ThE g0bL!N, LiquidWorm, Greg Linares.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in BlazeDVD 5.1 Professional and Blaze HDTV Player 6.0 via a maliciously crafted .PLF file. It leverages SEH overwrite with a universal address and includes shellcode for arbitrary code execution.
Description
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.
Exploits (4)
This exploit targets a buffer overflow vulnerability in BlazeDVD 5.1 Professional and Blaze HDTV Player 6.0 via a maliciously crafted .PLF file. It leverages SEH overwrite with a universal address and includes shellcode for arbitrary code execution.
This exploit targets a heap overflow vulnerability in BlazeVideo HDTV Player <= 3.5 via a maliciously crafted PLF playlist file. It leverages a JMP ESP instruction from user32.dll to execute Alpha2-encoded shellcode, achieving remote code execution.
This exploit demonstrates a stack-based buffer overflow in BlazeVideo HDTV Player <= v2.1 by crafting a malicious PLF file with an overly long path. It includes shellcode to execute calc.exe and provides multiple JMP ESP addresses for various Windows versions.
This exploit leverages a structured exception handler (SEH) overflow in BlazeVideo HDTV Player 6.6 Professional to bypass DEP and ASLR via ROP chains, ultimately executing a shellcode payload for remote code execution.