EIP-2026-118272
PRE-CVEApple iTunes - Playlist Buffer Overflow Download Shellcode
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118272. PoCs published by ATmaCA.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Apple iTunes (up to version 4.7) by crafting a malicious .m3u playlist file. It overwrites the return address (EIP) with a 'push eax' instruction from kernel32.dll and executes a XOR-encrypted shellcode that downloads and executes a payload from a specified URL.
Description
Apple iTunes - Playlist Buffer Overflow Download Shellcode
Exploits (1)
This exploit targets a buffer overflow vulnerability in Apple iTunes (up to version 4.7) by crafting a malicious .m3u playlist file. It overwrites the return address (EIP) with a 'push eax' instruction from kernel32.dll and executes a XOR-encrypted shellcode that downloads and executes a payload from a specified URL.