CVE-2010-0679
Hyleos ChemView 1.9.5.1 - Remote Code Execution via HyleosChemView ActiveX Control
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2010-0679.
PoCs published by Metasploit, Dz_attacker, including Metasploit module exploits/windows/browser/hyleos_chemviewx_activex.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Hyleos ChemView ActiveX Control (CVE-2010-0679) via the 'SaveAsMolFile' or 'ReadMolFile' methods, achieving remote code execution through heap spraying and shellcode injection.
Description
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument to the (1) SaveasMolFile and (2) ReadMolFile methods.
Exploits (3)
This Metasploit module exploits a stack-based buffer overflow in Hyleos ChemView ActiveX Control (CVE-2010-0679) via the 'SaveAsMolFile' or 'ReadMolFile' methods, achieving remote code execution through heap spraying and shellcode injection.
This exploit targets a stack-based buffer overflow in Hyleos ChemView ActiveX control (CVE-2010-0679) by setting an overly long value to 'SaveAsMolFile()', leading to arbitrary code execution. It uses Metasploit's framework to generate a malicious HTML file with obfuscated JavaScript.
This Metasploit module exploits a stack-based buffer overflow in Hyleos ChemView ActiveX Control (version 1.9.5.1) via the 'SaveAsMolFile' or 'ReadMolFile' methods. It uses heap spraying and JavaScript to trigger arbitrary code execution.