Viscom Software Movie Player Pro SDK ActiveX 6.8
Rocco Calvi
- Affected Vendor
- Viscom Software
- Affected Product
- Movie Player Pro SDK ActiveX
- Exploit Type
- Metasploit Module
- Metasploit Module
exploit/windows/browser/viscom_movieplayer_drawtext
Description
A stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control within MoviePlayer.ocx version 6.8.0.0. The vulnerability allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method. The exploit bypasses DEP and ASLR protections.