CVE-2012-2271
SkinCrafter 3.0 - Buffer Overflow via InitLicenKeys reg_name Argument
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-2271. PoCs published by saurabh sharma, metacom.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in SkinCrafter3_vs2005.dll via the InitLicenKeys function. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode.
Description
Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to execute arbitrary code via a long string in the first argument (aka the reg_name argument).
Exploits (2)
This exploit demonstrates a buffer overflow vulnerability in SkinCrafter3_vs2005.dll via the InitLicenKeys function. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode.
This exploit demonstrates a buffer overflow vulnerability in SkinCrafter3 ActiveX components (vs2005, vs2010, vs2008) via a crafted HTML page. It leverages SEH overwrites and shellcode execution to achieve remote code execution when loaded in Internet Explorer.