CVE-2009-1915
ICQ 6.5 - Stack-based Buffer Overflow via Long URL Parameter in .URL File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1915. PoCs published by Nine:Situations:Group.
AI-analyzed exploit summary This exploit generates a malicious .URL file that triggers a buffer overflow in ICQToolBar.dll when processed by Windows Explorer, leading to a crash (DoS) or potential code execution on unpatched systems. The PoC leverages a stack-based overflow via an overly long URL field in the shortcut file.
Description
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL file containing a long URL parameter, which triggers a crash when browsing a folder that contains this file.
Exploits (1)
This exploit generates a malicious .URL file that triggers a buffer overflow in ICQToolBar.dll when processed by Windows Explorer, leading to a crash (DoS) or potential code execution on unpatched systems. The PoC leverages a stack-based overflow via an overly long URL field in the shortcut file.