CVE-2010-2439

MoreAmp - Stack-based Buffer Overflow via Long Line in Song List File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2010-2439. PoCs published by Madjix, Sid3^effects.

AI-analyzed exploit summary This is a functional Metasploit module exploiting a SEH-based buffer overflow in MoreAmp 0.1.25 Beta via a crafted .m3u file. It leverages a known return address (0x7C86467B) to achieve arbitrary code execution on Windows XP SP3 Fr.

Description

Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

Exploits (3)

exploitdb WORKING POC VERIFIED
by Madjix · rubylocalwindows
https://www.exploit-db.com/exploits/14397

This is a functional Metasploit module exploiting a SEH-based buffer overflow in MoreAmp 0.1.25 Beta via a crafted .m3u file. It leverages a known return address (0x7C86467B) to achieve arbitrary code execution on Windows XP SP3 Fr.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MoreAmp 0.1.25 Beta
No auth needed
Prerequisites: Victim must open the malicious .m3u file in MoreAmp
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Madjix · perllocalwindows
https://www.exploit-db.com/exploits/13942

This exploit demonstrates a local stack-based buffer overflow in MoreAmp's .maf file parser, leveraging SEH overwrite with a jump to shellcode. The payload is crafted to trigger arbitrary code execution on Windows XP SP3 FR.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MoreAmp (version not specified)
No auth needed
Prerequisites: Victim must open the malicious .maf file in MoreAmp
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Sid3^effects · pythondoswindows
https://www.exploit-db.com/exploits/13934

This exploit generates a malformed .maf file with an oversized buffer (90,000 'A' characters) to trigger a buffer overflow in MoreAmp when the file is loaded via the 'Open Song List' feature. The PoC is designed for Windows XP SP3 and demonstrates a DoS condition, though it could potentially lead to arbitrary code execution with further refinement.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: MoreAmp (version unspecified)
No auth needed
Prerequisites: Victim must open the malicious .maf file in MoreAmp
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/13942
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/13934
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/59570

Scores

EPSS 0.0887
EPSS Percentile 92.8%

Details

CWE
CWE-119
Status published
Products (2)
moreforge/moreamp 0.1.23
moreforge/moreamp 0.1.25
Published Jun 24, 2010
Tracked Since Feb 18, 2026