Exploitation Summary
EIP tracks 3 public exploits for CVE-2011-10025.
PoCs published by Metasploit, Brandon Murphy, Brandon Murphy, sinn3r, including Metasploit module exploits/windows/fileformat/subtitle_processor_m3u_bof.
AI-analyzed exploit summary This Metasploit module exploits a Unicode SEH buffer overflow in Subtitle Processor 7.7.1 via a maliciously crafted .M3U file, achieving arbitrary code execution on Windows XP SP3 and Vista SP0.
Description
Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.
Exploits (3)
This Metasploit module exploits a Unicode SEH buffer overflow in Subtitle Processor 7.7.1 via a maliciously crafted .M3U file, achieving arbitrary code execution on Windows XP SP3 and Vista SP0.
This exploit targets a SEH Unicode buffer overflow in Subtitle Processor 7.7.1, leveraging a crafted M3U file to execute arbitrary shellcode (calc.exe) via a structured exception handler overwrite. The payload includes alignment techniques and an egghunter for reliable exploitation.
This Metasploit module exploits a Unicode buffer overflow in Subtitle Processor 7.7.1 via a maliciously crafted .M3U file, leveraging SEH overwrite and egghunter techniques for arbitrary code execution.
References (6)
Scores
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N