CVE-2009-1087
PPLive < 1.9.21 - Remote Code Execution via URI Handler Argument Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1087. PoCs published by Nine:Situations:Group.
AI-analyzed exploit summary This exploit leverages URI handlers in PPLive <= 1.9.21 to inject command line parameters, allowing remote DLL loading via UNC paths. It targets Internet Explorer to execute arbitrary code through the '/LoadModule' parameter.
Description
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit leverages URI handlers in PPLive <= 1.9.21 to inject command line parameters, allowing remote DLL loading via UNC paths. It targets Internet Explorer to execute arbitrary code through the '/LoadModule' parameter.