CVE-2009-1260

Ezbsystems Ultraiso < 9.3.3 - Memory Corruption

Title source: rule

Description

Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16666
exploitdb WORKING POC VERIFIED
by SkD · perllocalwindows
https://www.exploit-db.com/exploits/8343
metasploit WORKING POC GREAT
by jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ultraiso_ccd.rb

Scores

EPSS 0.7452
EPSS Percentile 98.9%

Details

CWE
CWE-119
Status published
Products (50)
ezbsystems/ultraiso 3.1
ezbsystems/ultraiso 3.1_sr1
ezbsystems/ultraiso 3.1_sr2
ezbsystems/ultraiso 4.0
ezbsystems/ultraiso 4.1
ezbsystems/ultraiso 4.5
ezbsystems/ultraiso 5.0
ezbsystems/ultraiso 5.1
ezbsystems/ultraiso 5.55
ezbsystems/ultraiso 5.55_sr-1
... and 40 more
Published Apr 07, 2009
Tracked Since Feb 18, 2026