Exploitation Summary
EIP tracks 3 public exploits for CVE-2010-5193.
PoCs published by Metasploit, Dr_IDE, including Metasploit module exploits/windows/browser/imgeviewer_tifmergemultifiles.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in the Viscom Image Viewer CP Pro 8.0/Gold 6.0 ActiveX control via the TifMergeMultiFiles() method. It includes ROP chains to bypass DEP and ASLR on various Windows versions with Java support.
Description
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro 8.0 and Gold 6.0 allows remote attackers to execute arbitrary code via a long strDelimit parameter.
Exploits (3)
This Metasploit module exploits a stack-based buffer overflow in the Viscom Image Viewer CP Pro 8.0/Gold 6.0 ActiveX control via the TifMergeMultiFiles() method. It includes ROP chains to bypass DEP and ASLR on various Windows versions with Java support.
This exploit targets a buffer overflow vulnerability in Image Viewer CP Gold 6 ActiveX control via the TIFMergeMultiFiles() method. It uses a heap spray technique to achieve remote code execution, delivering a calc.exe payload.
This Metasploit module exploits a stack-based buffer overflow in the ImageViewer2.OCX ActiveX control via the TifMergeMultiFiles() method, achieving remote code execution by bypassing DEP and ASLR on Windows systems with Java support.