Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-4755. PoCs published by His0k4.
AI-analyzed exploit summary This exploit targets a SEH overwrite vulnerability in Mercury Audio Player 1.21 via a maliciously crafted .pls file. It uses a known SEH handler address from msacm32.drv and includes a Metasploit-generated shellcode to execute arbitrary commands (e.g., calc.exe).
Description
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.
Exploits (2)
This exploit targets a SEH overwrite vulnerability in Mercury Audio Player 1.21 via a maliciously crafted .pls file. It uses a known SEH handler address from msacm32.drv and includes a Metasploit-generated shellcode to execute arbitrary commands (e.g., calc.exe).
This exploit targets a local stack overflow vulnerability in Mercury Audio Player 1.21 via a maliciously crafted .b4s file. It includes a header, buffer overflow payload, JMP ESP instruction, NOP sled, and shellcode to execute 'calc.exe' as a proof-of-concept.