CVE-2010-4321
Novell iPrint Client 5.52 - Stack-based Buffer Overflow via ienipp.ocx ActiveX Control
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2010-4321.
PoCs published by Metasploit, Dr_IDE, including Metasploit module exploits/windows/browser/novelliprint_getdriversettings_2.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in the Novell iPrint Client ActiveX control (ienipp.ocx) via the GetDriverSettings() property. It delivers a payload through a malicious HTML page, leveraging JavaScript to trigger the vulnerability and execute arbitrary code.
Description
Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to execute arbitrary code via a long argument to (1) the GetDriverSettings2 method, as reachable by (2) the GetDriverSettings method.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in the Novell iPrint Client ActiveX control (ienipp.ocx) via the GetDriverSettings() property. It delivers a payload through a malicious HTML page, leveraging JavaScript to trigger the vulnerability and execute arbitrary code.
This exploit targets a buffer overflow vulnerability in Novell iPrint's ActiveX control (CVE-2010-4321) via the GetDriverSettings() method. It uses a heap spray technique to achieve remote code execution by overwriting memory with shellcode that spawns calc.exe.
This Metasploit module exploits a stack buffer overflow in Novell iPrint Client 5.52 via the GetDriverSettings() property of the ienipp.ocx ActiveX control. It delivers a payload through a malicious HTML page, leveraging JavaScript to trigger the vulnerability and execute arbitrary code.