Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v7 - Exploits Update (Wed Aug 29 2007)

VLC Media Player Format String exploit

Exploits/Client Side  [Windows]




• Wed Aug 29 2007
This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by exploiting a vulnerability in VLC 0.86, which allows user-assisted remote attackers to execute code via a crafted OGG file that triggers format string and overwrites a subroutine pointer during rendering.

Exploits Vulnerabiltiy: CVE-2007-3316



< Back to Product Updates