Exploitation Summary
EIP tracks 3 public exploits for CVE-2009-4588.
PoCs published by Metasploit, shinnai, including Metasploit module exploits/windows/browser/awingsoft_web3d_bof.
AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in AwingSoft Web3D Player's 'SceneURL()' property (CVE-2009-4588). It targets Internet Explorer 6/7 on Windows XP SP0-SP3 by delivering a malicious HTML page that triggers arbitrary code execution.
Description
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386. NOTE: some of these details are obtained from third party information.
Exploits (3)
This is a Metasploit module exploiting a buffer overflow in AwingSoft Web3D Player's 'SceneURL()' property (CVE-2009-4588). It targets Internet Explorer 6/7 on Windows XP SP0-SP3 by delivering a malicious HTML page that triggers arbitrary code execution.
This exploit targets a buffer overflow vulnerability in AwingSoft Web3D Player's WindsPly.ocx via the SceneURL() method. It constructs a malicious string to overflow the buffer, potentially leading to remote code execution.
This is a Metasploit module exploiting a buffer overflow in AwingSoft Web3D Player's 'SceneURL' property (CVE-2009-4588). It targets Internet Explorer on Windows XP by overrunning a buffer with a long string, leading to arbitrary code execution.