Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2570. PoCs published by Nine:Situations:Group.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Symantec Fax Viewer Control v10 (DCCFAXVW.DLL) via Internet Explorer 7. It uses a heap spray technique to achieve remote code execution by triggering the overflow with a maliciously crafted string.
Description
Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax Pro 10.03 allows remote attackers to execute arbitrary code via a long argument to the AppendFax method.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Symantec Fax Viewer Control v10 (DCCFAXVW.DLL) via Internet Explorer 7. It uses a heap spray technique to achieve remote code execution by triggering the overflow with a maliciously crafted string.