CVE-2011-5170

CCMPlayer 1.5 - Remote Code Execution via Long Track Name in m3u Playlist

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2011-5170. PoCs published by Metasploit, Rh0, including Metasploit module exploits/windows/fileformat/ccmplayer_m3u_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in CCMPlayer 1.5 via a maliciously crafted .m3u file. It leverages SEH overwrites and a long jump to execute arbitrary shellcode, achieving remote code execution.

Description

Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/18195

This Metasploit module exploits a stack-based buffer overflow in CCMPlayer 1.5 via a maliciously crafted .m3u file. It leverages SEH overwrites and a long jump to execute arbitrary shellcode, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CCMPlayer 1.5
No auth needed
Prerequisites: Victim must open the malicious .m3u file in CCMPlayer 1.5
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Rh0 · rubylocalwindows
https://www.exploit-db.com/exploits/18178

This exploit targets a stack-based buffer overflow in CCMPlayer 1.5 via a maliciously crafted .m3u file. It leverages SEH overwrites and a long jump to execute arbitrary shellcode, achieving remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CCMPlayer 1.5
No auth needed
Prerequisites: Victim must open the malicious .m3u file in CCMPlayer 1.5
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by Rh0 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ccmplayer_m3u_bof.rb

This Metasploit module exploits a stack-based buffer overflow in CCMPlayer 1.5 via a maliciously crafted m3u playlist file. It overwrites the SEH exception record to achieve arbitrary code execution on Windows platforms.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CCMPlayer 1.5
No auth needed
Prerequisites: Victim must open the malicious m3u file in CCMPlayer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18195
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71573
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18178
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77453

Scores

EPSS 0.3197
EPSS Percentile 98.1%

Details

CWE
CWE-119
Status published
Products (1)
castillobueno/ccmplayer 1.5
Published Sep 15, 2012
Tracked Since Feb 18, 2026