CVE-2009-1612
EXPLOITED IN THE WILDBaofeng Storm - Stack-based Buffer Overflow via OnBeforeVideoDownload Method
Title source: llmExploitation Summary
CVE-2009-1612 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 3 public exploits from researchers including Metasploit, MITBOY, jduck, including a Metasploit module exploits/windows/browser/baofeng_storm_onbeforevideodownload.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in BaoFeng Storm media Player ActiveX control (mps.dll) via the 'OnBeforeVideoDownload' method. It uses heap spraying and shellcode execution to achieve remote code execution.
Description
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 3.09.04.17 and earlier are also affected.
Exploits (3)
This Metasploit module exploits a buffer overflow in BaoFeng Storm media Player ActiveX control (mps.dll) via the 'OnBeforeVideoDownload' method. It uses heap spraying and shellcode execution to achieve remote code execution.
This exploit targets a remote code execution vulnerability in BaoFeng's mps.dll via the OnBeforeVideoDownload function. It uses a heap spray technique to achieve reliable exploitation by overflowing a buffer with a crafted payload.
This Metasploit module exploits a buffer overflow in BaoFeng Storm media Player ActiveX control (mps.dll) via the 'OnBeforeVideoDownload' method. It uses heap spraying and JavaScript obfuscation to achieve remote code execution.