CVE-2009-1449
CoolPlayer Portable 2.19.1 - Stack-based Buffer Overflow via Skin File PlaylistSkin Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1449. PoCs published by Stack.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in CoolPlayer Portable 2.19.1 via a maliciously crafted skin.ini file. It overwrites the EIP register with a JMP ESP address from ntdll.dll and executes a calc.exe payload using alphanumeric shellcode.
Description
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSkin parameter. NOTE: this may overlap CVE-2008-5735.
Exploits (1)
This exploit targets a buffer overflow vulnerability in CoolPlayer Portable 2.19.1 via a maliciously crafted skin.ini file. It overwrites the EIP register with a JMP ESP address from ntdll.dll and executes a calc.exe payload using alphanumeric shellcode.