K-Lite Mega Codec Pack 3.5.7.0 Local Windows Explorer DoS PoC

2008.11.15
Credit: Aodrulez
Risk: Low
Local: Yes
Remote: No


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: None
Availability impact: Partial

K-Lite Mega Codec Pack based Local Windows Explorer DOS PoC. Version:3.5.7.0 "vsfilter.dll"(Version 1.0.1.4) that comes bundled with the above Codec Pack crashes when we try to use,select or even highlight the attached "Test7.flv" file in Windows Explorer,causing Explorer to Crash. Greetz fly out to: 1]LiquidWorm : For being so nice.....n guiding me.. :) 2]str0ke : For goin thru all my silly e-mails. 3]Amforked() : My mentor. ------------------------------------------------------------------ By: Aodrulez, www.OrchidSeven.com, aodrulez.blogspot.com. Email: f3arm3d3ar@gmail.com ------------------------------------------------------------------

References:

http://xforce.iss.net/xforce/xfdb/45446
http://www.securityfocus.com/bid/31400
http://www.milw0rm.com/exploits/6565
http://packetstormsecurity.org/filedesc/klite-dos-tgz.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2020, cxsecurity.com

 

Back to Top