CORE IMPACT v7 - Exploits Update (Wed Aug 29 2007)
VLC Media Player Format String exploit
Exploits/Client Side [Windows]
Wed Aug 29 2007
This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by exploiting a vulnerability in VLC 0.86, which allows user-assisted remote attackers to execute code via a crafted OGG file that triggers format string and overwrites a subroutine pointer during rendering.
Exploits Vulnerabiltiy: CVE-2007-3316











