CVE-2011-5003

Avid Media Composer < 5.5.3 - Remote Code Execution via Phonetic Indexer Long Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-5003. PoCs published by Nick Freeman, including Metasploit module exploits/windows/misc/avidphoneticindexer.

AI-analyzed exploit summary This is a Metasploit module exploiting a stack buffer overflow in AvidPhoneticIndexer.exe (port 4659) in Avid Media Composer 5.5. It uses a SEH pivot and ROP chain to achieve arbitrary code execution.

Description

Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Nick Freeman · rubyremotewindows
https://www.exploit-db.com/exploits/18183

This is a Metasploit module exploiting a stack buffer overflow in AvidPhoneticIndexer.exe (port 4659) in Avid Media Composer 5.5. It uses a SEH pivot and ROP chain to achieve arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Avid Media Composer <= 5.5.3
No auth needed
Prerequisites: Network access to the vulnerable service on port 4659 or 4660
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/avidphoneticindexer.rb

This Metasploit module exploits a stack buffer overflow in AvidPhoneticIndexer.exe (port 4659) by sending a crafted payload to achieve remote code execution. It uses a ROP chain to bypass DEP and execute shellcode.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Avid Media Composer 5.5
No auth needed
Prerequisites: Network access to the target system · AvidPhoneticIndexer.exe running on port 4659 or 4660
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18183
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/77376
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50843
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71514
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47047

Scores

EPSS 0.6281
EPSS Percentile 99.1%

Details

CWE
CWE-119
Status published
Products (1)
avid/media_composer < 5.5.3
Published Dec 25, 2011
Tracked Since Feb 18, 2026