CVE-2009-0885
Media Commands 1.0 - Remote Code Execution via Long String in Playlist File
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-0885. PoCs published by His0k4, Hakxer.
AI-analyzed exploit summary This exploit demonstrates a local SEH overwrite vulnerability in Media Commands (m3u file) by crafting a malicious .m3u file with a buffer overflow payload. It includes a shellcode to execute 'calc.exe' and is tested on Windows XP Pro SP2 Fr.
Description
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.
Exploits (2)
This exploit demonstrates a local SEH overwrite vulnerability in Media Commands (m3u file) by crafting a malicious .m3u file with a buffer overflow payload. It includes a shellcode to execute 'calc.exe' and is tested on Windows XP Pro SP2 Fr.
This Perl script generates a malicious .lrc file containing a buffer overflow payload and a long HTTP URL to trigger a crash in Media Commands software. The payload includes shellcode likely intended for remote code execution.