CVE-2009-1260
UltraISO < 9.3.3 - Stack-Based Buffer Overflow via Crafted CCD or IMG File
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2009-1260.
PoCs published by Metasploit, SkD, jduck, including Metasploit module exploits/windows/fileformat/ultraiso_ccd.
AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in UltraISO's CCD file parsing functionality. It leverages SEH overwrites to achieve arbitrary code execution when a victim opens a maliciously crafted CCD file.
Description
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.
Exploits (3)
This exploit targets a stack-based buffer overflow in UltraISO's CCD file parsing functionality. It leverages SEH overwrites to achieve arbitrary code execution when a victim opens a maliciously crafted CCD file.
This exploit targets a buffer overflow vulnerability in UltraISO <= 9.3.3.2685 by crafting a malicious CCD/IMG file. The exploit triggers arbitrary code execution when the file is opened in UltraISO.
This Metasploit module exploits a stack-based buffer overflow in UltraISO by crafting a malicious .CCD file. It leverages SEH overwrites to achieve arbitrary code execution when the victim opens the file.