CVE-2009-5109

Mini-Stream Ripper 3.0.1.1 - Stack-Based Buffer Overflow via .pls File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2009-5109. PoCs published by Metasploit, jacky, mr_me, including Metasploit module exploits/windows/misc/mini_stream.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Mini-Stream 3.0.1.1 by crafting a malicious PLS file, allowing arbitrary code execution via a JMP ESP instruction in USER32.dll or SHELL32.dll.

Description

Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/18082

This Metasploit module exploits a stack buffer overflow in Mini-Stream 3.0.1.1 by crafting a malicious PLS file, allowing arbitrary code execution via a JMP ESP instruction in USER32.dll or SHELL32.dll.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mini-Stream 3.0.1.1
No auth needed
Prerequisites: Victim must open a malicious PLS file hosted by the attacker
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by jacky · perllocalwindows
https://www.exploit-db.com/exploits/10782

This exploit demonstrates a buffer overflow vulnerability in Mini-Stream Ripper v3.0.1.1 by crafting a malicious .pls file with a long string of 'A's to overwrite the EIP and redirect execution to shellcode in the ESP register. The exploit uses a universal return address from MSRcodec00.dll to achieve reliable code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mini-Stream Ripper v3.0.1.1
No auth needed
Prerequisites: Victim must open the malicious .pls file in Mini-Stream Ripper
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by mr_me · clocalwindows
https://www.exploit-db.com/exploits/10745

This exploit demonstrates a local buffer overflow vulnerability in Mini-stream Ripper 3.0.1.1 by crafting a malicious .pls file that triggers a stack-based overflow, leading to arbitrary code execution via a reverse shell payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mini-stream Ripper 3.0.1.1
No auth needed
Prerequisites: Victim must open the malicious .pls file in Mini-stream Ripper
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by dijital1 · pythonlocalwindows
https://www.exploit-db.com/exploits/10747

This exploit targets a buffer overflow vulnerability in Mini-Stream 3.0.1.1 by crafting a malicious .pls file with a long shellcode payload and a JMP ESP address to achieve remote code execution on Windows XP SP2/SP3.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mini-Stream 3.0.1.1
No auth needed
Prerequisites: Victim must open the malicious .pls file
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Unknown · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/mini_stream.rb

This Metasploit module exploits a stack buffer overflow in Mini-Stream 3.0.1.1 by crafting a malicious PLS file, allowing arbitrary code execution via a JMP ESP instruction in USER32.dll or SHELL32.dll.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mini-Stream 3.0.1.1
No auth needed
Prerequisites: Victim must open a malicious PLS file hosted on an attacker-controlled server
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10782
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18082
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10745
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10747
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/61341

Scores

EPSS 0.3294
EPSS Percentile 98.1%

Details

CWE
CWE-119
Status published
Products (1)
mini-stream/ripper 3.0.1.1
Published Dec 25, 2011
Tracked Since Feb 18, 2026