CVE-2009-1800

EXPLOITED IN THE WILD

Chinagames iGame 2009 - Stack-Based Buffer Overflow via CreateChinagames Method

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-1800 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including etirah.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the CGAgent.dll ActiveX control via the CreateChinagames method. It uses a heap spray technique to achieve remote code execution by overwriting memory with shellcode.

Description

Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by etirah · htmlremotewindows
https://www.exploit-db.com/exploits/8758

This exploit targets a buffer overflow vulnerability in the CGAgent.dll ActiveX control via the CreateChinagames method. It uses a heap spray technique to achieve remote code execution by overwriting memory with shellcode.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ChinaGames CGAgent.dll (version unspecified)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · ActiveX control must be installed and enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34871
Exploit x_refsource_misc
http://www.cisrt.org/enblog/read.php?245
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35005

Scores

EPSS 0.0789
EPSS Percentile 92.2%

Details

VulnCheck KEV 2009-05-28
InTheWild.io 2009-05-28
CWE
CWE-119
Status published
Products (1)
chinagames/igame 2009
Published May 28, 2009
Tracked Since Feb 18, 2026