Exploitation Summary
EIP tracks 2 public exploits for CVE-2012-4711.
PoCs published by Metasploit, Lucas Apa, Carlos Mario Penagos Hollman, juan vazquez, including Metasploit module exploits/windows/fileformat/kingview_kingmess_kvl.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow vulnerability in KingView <= 6.55 via a malformed .kvl log file. It leverages insecure usage of sprintf in KingMess.exe to achieve remote code execution when the victim opens the file.
Description
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet.
Exploits (2)
This Metasploit module exploits a buffer overflow vulnerability in KingView <= 6.55 via a malformed .kvl log file. It leverages insecure usage of sprintf in KingMess.exe to achieve remote code execution when the victim opens the file.
This Metasploit module exploits a buffer overflow vulnerability in KingView's KingMess.exe when parsing malformed .kvl log files. It leverages a stack-based overflow via insecure sprintf usage to achieve remote code execution.