CVE-2016-0015
HIGHMicrosoft Windows - Remote Code Execution via Crafted File in DirectShow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-0015. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates a heap corruption buffer underflow in devenum.dll!DeviceMoniker::Load() due to improper NULL termination of a user-supplied string. It leverages a crafted Word document with an embedded OLE object to trigger the vulnerability, leading to potential remote code execution.
Description
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap Corruption Remote Code Execution Vulnerability."
Exploits (1)
The exploit demonstrates a heap corruption buffer underflow in devenum.dll!DeviceMoniker::Load() due to improper NULL termination of a user-supplied string. It leverages a crafted Word document with an embedded OLE object to trigger the vulnerability, leading to potential remote code execution.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H