CVE-2010-4588
WMI Administrative Tools < 1.1 - Remote Code Execution via WBEMSingleView.ocx ReleaseContext Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4588. PoCs published by WooYun.
AI-analyzed exploit summary This exploit leverages a heap spray technique to trigger a use-after-free vulnerability in the Adobe Flash Player ActiveX control (CVE-2010-4588), executing arbitrary shellcode (calc.exe in this case) via a crafted HTML file.
Description
The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary code via a crafted argument to the ReleaseContext method, a different vector than CVE-2010-3973, possibly an untrusted pointer dereference.
Exploits (1)
This exploit leverages a heap spray technique to trigger a use-after-free vulnerability in the Adobe Flash Player ActiveX control (CVE-2010-4588), executing arbitrary shellcode (calc.exe in this case) via a crafted HTML file.