CVE-2010-20042

HIGH

Xion Audio Player <1.0.126 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2010-20042. PoCs published by Metasploit, anT!-Tr0J4n, corelanc0d3r, including Metasploit module exploits/windows/fileformat/xion_m3u_sehbof.

AI-analyzed exploit summary This exploit targets a Unicode stack buffer overflow in Xion Audio Player v1.0.126 via a malformed M3U file, leveraging SEH overwrite and an egghunter for payload execution.

Description

Xion Audio Player versions 1.0.126 and prior are vulnerable to a Unicode-based stack buffer overflow triggered by opening a specially crafted .m3u playlist file. The file contains an overly long string that overwrites the Structured Exception Handler (SEH) chain, allowing an attacker to hijack execution flow and run arbitrary code.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16653

This exploit targets a Unicode stack buffer overflow in Xion Audio Player v1.0.126 via a malformed M3U file, leveraging SEH overwrite and an egghunter for payload execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Xion Audio Player v1.0.126
No auth needed
Prerequisites: Victim must open a malformed M3U file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by anT!-Tr0J4n · perldoswindows
https://www.exploit-db.com/exploits/15598

This exploit demonstrates a buffer overflow vulnerability in Xion Audio Player 1.0.126 by creating a malicious .m3u8 file with a long string of 'A' characters (3569 bytes). When opened and played in the vulnerable software, it triggers a crash, potentially allowing arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Xion Audio Player 1.0.126
No auth needed
Prerequisites: Victim must open the malicious .m3u8 file in Xion Audio Player and press play
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by corelanc0d3r · pythonlocalwindows
https://www.exploit-db.com/exploits/14633

This exploit targets a stack-based buffer overflow in Xion 1.0.125 via a maliciously crafted M3U file. It leverages SEH overwrite with Unicode-compatible shellcode to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Xion 1.0.125
No auth needed
Prerequisites: Victim must open the malicious M3U file in Xion 1.0.125
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by s-dz · perldoswindows
https://www.exploit-db.com/exploits/14517

This exploit generates a maliciously crafted M3U file with an excessively long string to trigger a buffer overflow in Xion Audio Player 1.0.125. The PoC is designed to cause a denial-of-service (DoS) by crashing the application.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Xion Audio Player 1.0.125
No auth needed
Prerequisites: Xion Audio Player 1.0.125 installed on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/xion_m3u_sehbof.rb

This Metasploit module exploits a Unicode stack buffer overflow in Xion Audio Player v1.0.126 via a malformed M3U file, leveraging SEH overwrite and egghunter techniques for reliable payload execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Xion Audio Player v1.0.126
No auth needed
Prerequisites: Victim must open a malicious M3U file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 8.4
EPSS 0.0970
EPSS Percentile 93.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
Xion/Audio Player < 1.0.126
Published Aug 20, 2025
Tracked Since Feb 18, 2026