CVE-2017-8869
HIGHMediaCoder 0.8.48.5888 - Remote Code Execution via Crafted .m3u File
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2017-8869.
PoCs published by Muhann4d, tankist0x01, metacom, including Metasploit module exploits/windows/fileformat/mediacoder_m3u.
AI-analyzed exploit summary This exploit demonstrates a local buffer overflow vulnerability in MediaCoder 0.8.48.5888 by crafting a malicious .m3u file that triggers an SEH overwrite, leading to arbitrary code execution (calc.exe payload).
Description
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
Exploits (3)
This exploit demonstrates a local buffer overflow vulnerability in MediaCoder 0.8.48.5888 by crafting a malicious .m3u file that triggers an SEH overwrite, leading to arbitrary code execution (calc.exe payload).
This is a functional exploit for CVE-2017-8869, targeting a local buffer overflow in MediaCoder 0.8.48.5888 via a crafted .m3u file. It includes a reverse shell payload generated with msfvenom, leveraging SEH overwrite techniques.
This Metasploit module exploits a buffer overflow in MediaCoder 0.8.21-0.8.22 via a maliciously crafted .M3U file, achieving remote code execution through a ROP chain to bypass DEP on Windows 7.
References (1)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H