CVE-2009-1071

Icarus 2.0 - Stack-based Buffer Overflow via Crafted PGN File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-1071. PoCs published by germaya_x, His0k4.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Icarus 2.0 via a malformed .PGn file, leveraging SEH overwrite and shellcode execution for local privilege escalation or arbitrary code execution.

Description

Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by germaya_x · perllocalwindows
https://www.exploit-db.com/exploits/9628

This exploit targets a buffer overflow vulnerability in Icarus 2.0 via a malformed .PGn file, leveraging SEH overwrite and shellcode execution for local privilege escalation or arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Icarus 2.0
No auth needed
Prerequisites: Victim must open the malformed .PGn file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8236

This exploit targets a local stack overflow vulnerability in Icarus 2.0, using two payloads (EIP and SEH) to achieve arbitrary code execution. The payloads include shellcode and NOP sleds to trigger the vulnerability when loaded via the application's PGN file format.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Icarus 2.0
No auth needed
Prerequisites: Victim must open the malicious PGN file in Icarus 2.0
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49309
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34167
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8236
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/52780
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34368

Scores

EPSS 0.0603
EPSS Percentile 92.4%

Details

CWE
CWE-119
Status published
Products (1)
randomsoftware/icarus 2.0
Published Mar 26, 2009
Tracked Since Feb 18, 2026