CVE-2009-1831

Nullsoft Winamp < 5.552 - Remote Code Execution via Crafted MAKI File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2009-1831. PoCs published by Metasploit, n00b, His0k4, including Metasploit module exploits/windows/fileformat/winamp_maki_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Winamp 5.55 via a crafted MAKI file, leveraging an insecure memmove operation in gen_ff.dll. It generates a malicious mcvcore.maki file that triggers the vulnerability when parsed by Winamp.

Description

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/21256

This Metasploit module exploits a stack-based buffer overflow in Winamp 5.55 via a crafted MAKI file, leveraging an insecure memmove operation in gen_ff.dll. It generates a malicious mcvcore.maki file that triggers the vulnerability when parsed by Winamp.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp 5.55
No auth needed
Prerequisites: Victim must install the crafted MAKI file in the Winamp scripts directory or use a skin containing it
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by n00b · clocalwindows
https://www.exploit-db.com/exploits/8783

This exploit targets an integer overflow vulnerability in Winamp 5.551's MAKI parsing functionality. It triggers an exception handler overwrite to execute arbitrary shellcode, demonstrated with a calc.exe payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp 5.551
No auth needed
Prerequisites: Victim must open a malicious MAKI file in Winamp 5.551
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8770

This exploit targets a MAKI script parsing vulnerability in Winamp <= 5.55, leveraging a SEH overwrite to achieve remote code execution. The payload is embedded in a crafted MAKI file, designed to trigger the vulnerability when parsed by Winamp.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp <= 5.55
No auth needed
Prerequisites: Victim must open the malicious MAKI file in Winamp
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Encrypt3d.M!nd · perllocalwindows
https://www.exploit-db.com/exploits/8772

This exploit targets a universal integer overflow vulnerability in Winamp <= 5.55 via a malicious MAKI script. It crafts a file 'mcvcore.maki' with a header, exploit payload, and shellcode to achieve remote code execution when placed in the Winamp skins directory.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp <= 5.55
No auth needed
Prerequisites: Access to the target system's file system to place the malicious MAKI script in the Winamp skins directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by n00b · cdoswindows
https://www.exploit-db.com/exploits/8767

This exploit triggers an integer overflow in Winamp 5.551 by crafting a malicious MAKI file, leading to a buffer overflow and potential control over exception handlers. The PoC generates a file that, when parsed, overwrites the SEH record.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp 5.551
No auth needed
Prerequisites: Winamp 5.551 installed · Ability to place the malicious MAKI file in the target directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Monica Sojeong Hong, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/winamp_maki_bof.rb

This Metasploit module exploits a stack-based buffer overflow in Winamp 5.55 via a crafted MAKI file, leveraging an insecure memmove operation in gen_ff.dll. It generates a malicious mcvcore.maki file to achieve remote code execution when parsed by the vulnerable software.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp 5.55
No auth needed
Prerequisites: Victim must install the crafted mcvcore.maki file in the Winamp scripts directory or use a skin containing it
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35052
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8783
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50664
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15683
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8770
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8767
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8772

Scores

EPSS 0.3634
EPSS Percentile 98.3%

Details

CWE
CWE-189
Status published
Products (43)
nullsoft/winamp 2.0
nullsoft/winamp 2.4
nullsoft/winamp 2.5e
nullsoft/winamp 2.6x
nullsoft/winamp 2.7x
nullsoft/winamp 2.10
nullsoft/winamp 2.24
nullsoft/winamp 2.50
nullsoft/winamp 2.60 (3 CPE variants)
nullsoft/winamp 2.61 (2 CPE variants)
... and 33 more
Published May 29, 2009
Tracked Since Feb 18, 2026