Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-4761. PoCs published by ThE g0bL!N, Stack.
AI-analyzed exploit summary This exploit targets a local stack overflow vulnerability in RM Downloader via a malformed .smi file. It uses a JMP ESP instruction from kernel32.dll to redirect execution to a calc.exe payload encoded with PexAlphaNum.
Description
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file.
Exploits (2)
This exploit targets a local stack overflow vulnerability in RM Downloader via a malformed .smi file. It uses a JMP ESP instruction from kernel32.dll to redirect execution to a calc.exe payload encoded with PexAlphaNum.
This exploit targets a buffer overflow vulnerability in RM Downloader via a maliciously crafted .smi file. It uses a universal return address and shellcode to achieve remote code execution.