CVE-2009-3658
HIGHAOL SuperBuddy ActiveX Control - Use-After-Free via SetSuperBuddy Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3658. PoCs published by Trotzkista.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Sb.SuperBuddy.1 ActiveX control (CVE-2009-3658) by triggering a heap spray with shellcode and a long string to achieve remote code execution.
Description
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Sb.SuperBuddy.1 ActiveX control (CVE-2009-3658) by triggering a heap spray with shellcode and a long string to achieve remote code execution.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H