CVE-2009-0824

EXPLOITED RANSOMWARE

Elaborate Bytes ElbyCDIO.sys <=6.0.2.0 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-0824 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including Nikita Tarakanov.

AI-analyzed exploit summary This is a vulnerability writeup describing multiple buffer overflow vulnerabilities in various SlySoft products. It does not contain exploit code but references a binary exploit available via a GitLab link.

Description

Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Nikita Tarakanov · textlocalwindows
https://www.exploit-db.com/exploits/32850

This is a vulnerability writeup describing multiple buffer overflow vulnerabilities in various SlySoft products. It does not contain exploit code but references a binary exploit available via a GitLab link.

Classification
Writeup 90%
Attack Type
Rce | Dos
Complexity
Moderate
Reliability
Theoretical
Target: SlySoft AnyDVD 6.5.2.2, SlySoft AnyDVD HD 6.5.2.2, SlySoft Virtual CloneDrive 5.4.2.3, SlySoft CloneDVD 2.9.2.0, SlySoft CloneCD 5.3.1.3
No auth needed
Prerequisites: Local access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Various Sources x_refsource_misc
http://en.securitylab.ru/lab/PT-2009-11
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34288
Various Sources x_refsource_confirm
http://www.slysoft.com/download/changes_clonedvd.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49232
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34289
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34269
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34287
Various Sources x_refsource_confirm
http://www.slysoft.com/download/changes_anydvd.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34103
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/52679
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/501713/100/0/threaded

Scores

EPSS 0.0012
EPSS Percentile 30.3%

Details

VulnCheck KEV 2018-03-06
Ransomware Use Confirmed
CWE
CWE-119
Status published
Products (4)
slysoft/anydvd < 6.5.2.2
slysoft/clonecd < 5.3.1.3
slysoft/clonedvd < 2.9.2.0
slysoft/virtualclonedrive < 5.4.2.3
Published Mar 14, 2009
Tracked Since Feb 18, 2026