CVE-2009-1092

GeoVision LIVEAUDIO.LiveAudioCtrl.1 ActiveX Control 7.0 - Use-After-Free via GetAudioPlayingTime Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1092. PoCs published by Nine:Situations:Group.

AI-analyzed exploit summary This exploit targets a use-after-free vulnerability in the GeoVision LiveAudio ActiveX control (CVE-2009-1092) by passing malformed objects to the GetAudioPlayingTime() method, leading to arbitrary code execution via a Metasploit-generated Alpha2-encoded shellcode that launches calc.exe.

Description

Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nine:Situations:Group · htmlremotewindows
https://www.exploit-db.com/exploits/8206

This exploit targets a use-after-free vulnerability in the GeoVision LiveAudio ActiveX control (CVE-2009-1092) by passing malformed objects to the GetAudioPlayingTime() method, leading to arbitrary code execution via a Metasploit-generated Alpha2-encoded shellcode that launches calc.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GeoVision LiveAudio ActiveX Control (version 7.0)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49238
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34115
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8206
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/501773/100/0/threaded

Scores

EPSS 0.0881
EPSS Percentile 94.5%

Details

CWE
CWE-399
Status published
Products (1)
geovision/liveaudio_activex_control 7.0
Published Mar 25, 2009
Tracked Since Feb 18, 2026