CVE-2009-1674

Microchip MPLAB IDE 8.30 - Stack-Based Buffer Overflow via Long .cof Pathname in .mcp File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1674. PoCs published by His0k4.

AI-analyzed exploit summary This exploit targets a structured exception handler (SEH) overwrite vulnerability in MPLAB IDE 8.30 by crafting a malicious .mcp project file. It includes shellcode to execute arbitrary commands (e.g., calc.exe) and demonstrates a classic buffer overflow with SEH bypass.

Description

Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.

Exploits (1)

exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8656

This exploit targets a structured exception handler (SEH) overwrite vulnerability in MPLAB IDE 8.30 by crafting a malicious .mcp project file. It includes shellcode to execute arbitrary commands (e.g., calc.exe) and demonstrates a classic buffer overflow with SEH bypass.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MPLAB IDE 8.30
No auth needed
Prerequisites: Victim must open the malicious .mcp file in MPLAB IDE 8.30
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8656
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35054

Scores

EPSS 0.0490
EPSS Percentile 91.0%

Details

CWE
CWE-119
Status published
Products (1)
microchip/mplab_ide 8.30
Published May 18, 2009
Tracked Since Feb 18, 2026