CVE-2012-4992

FlashFXP 4.2 - Authenticated Remote Code Execution via Long Unicode String to TListbox or TComboBox

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4992. PoCs published by Vulnerability-Lab.

AI-analyzed exploit summary The document describes a buffer overflow vulnerability in FlashFXP v4.1.8.1701, triggered by manipulating the Skip-List filter with a large Unicode string, leading to ECX and EIP overwrite. It includes detailed steps for reproduction and crash logs but lacks executable exploit code.

Description

Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

Exploits (1)

exploitdb WRITEUP
by Vulnerability-Lab · textremotewindows
https://www.exploit-db.com/exploits/18555

The document describes a buffer overflow vulnerability in FlashFXP v4.1.8.1701, triggered by manipulating the Skip-List filter with a large Unicode string, leading to ECX and EIP overwrite. It includes detailed steps for reproduction and crash logs but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: FlashFXP v4.1.8.1701
No auth needed
Prerequisites: Local or remote access to FlashFXP client · Ability to modify Skip-List filter settings
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18555
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/79767
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73626
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-03/0002.html
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2012/Mar/7
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52259

Scores

EPSS 0.1769
EPSS Percentile 96.8%

Details

CWE
CWE-119
Status published
Products (1)
flashfxp/flashfxp 4.2
Published Sep 19, 2012
Tracked Since Feb 18, 2026