CVE-2009-4754

Mercury Audio Player 1.21 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-4754. PoCs published by His0k4, SirGod.

AI-analyzed exploit summary This exploit targets a SEH overwrite vulnerability in Mercury Audio Player 1.21 via a crafted .m3u file. It includes shellcode for executing calc.exe and an egghunter to locate the payload in memory.

Description

Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8583

This exploit targets a SEH overwrite vulnerability in Mercury Audio Player 1.21 via a crafted .m3u file. It includes shellcode for executing calc.exe and an egghunter to locate the payload in memory.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury Audio Player 1.21
No auth needed
Prerequisites: Victim must open the malicious .m3u file in Mercury Audio Player 1.21
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by SirGod · perldoswindows
https://www.exploit-db.com/exploits/8578

This exploit generates a malicious .M3U file with a long string of 'A' characters to trigger a local stack overflow in Mercury Audio Player 1.21. The PoC demonstrates the vulnerability but does not include a payload for execution.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Mercury Audio Player 1.21
No auth needed
Prerequisites: Victim must open the malicious .M3U file in Mercury Audio Player 1.21
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50288
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34957
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8583
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34788
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8578

Scores

EPSS 0.0603
EPSS Percentile 92.4%

Details

CWE
CWE-119
Status published
Products (1)
mercuryaudio/audio_player 1.21
Published Mar 29, 2010
Tracked Since Feb 18, 2026