Core Impact Pro Exploits and Security Updates

When you buy Core Impact Pro, we provide real-time updates including new penetration testing exploits and tests for additional platforms as they become available. We advise you of any new modules by email, after which you can download them directly from within Core Impact Pro. All product updates are free during the license period. You're always on the cutting edge of vulnerability and threat intelligence because Core Impact Pro keeps you there.

Use the controls below to navigate Core Impact exploits and other modules.

Released Date Titlesort descending Description Vulnerabilty Category Platform
03.21.2011 Adobe Flash Player SWF File Uninitialized Memory Exploit A vulnerability has been identified in Adobe Flash Player, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an uninitialized memory access triggered by a specially crafted .SWF file, which could be exploited by attackers to execute arbitrary code. This vulnerability has been found exploited in-the-wild during March 2011. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. CVE-2011-0609 Exploits/Client Side Windows
02.12.2013 Adobe Flash Player SWF Load Crafted Module Exploit This module exploits a vulnerability in Adobe Flash Player triggered when processing a SWF file and this load a crafted dll module. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. CVE-2013-0633 Exploits/Client Side Windows
02.14.2013 Adobe Flash Player SWF Load Crafted Module Exploit Update This module exploits a vulnerability in Adobe Flash Player triggered when processing a SWF file and this load a crafted dll module. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This update improves the reliability of the exploit. CVE-2013-0633 Exploits/Client Side Windows
05.18.2014 Adobe Flash Player SWF Load Crafted Module Exploit Update 2 This module exploits a vulnerability in Adobe Flash Player triggered when processing a SWF file and this load a crafted dll module. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This update improves the reliability of the exploit. CVE-2013-0634 Exploits/Client Side Windows
04.25.2014 Adobe Flash Player Type Confusion Exploit This module exploits a type confusion vulnerability in Adobe Flash Player. This vulnerability has been found exploited in-the-wild during December 2013. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. CVE-2013-5331 Exploits/Client Side Windows
05.05.2014 Adobe Flash Player Type Confusion Exploit Update This module exploits a type confusion vulnerability in Adobe Flash Player. This vulnerability has been found exploited in-the-wild during December 2013. This update improves module documentation, exploit code and adds more vulnerable Adobe Flash Player versions. CVE-2013-5331 Exploits/Client Side Windows
07.02.2012 Adobe Flash Player _error Object Confusion Exploit This module exploits an object type confusion vulnerability in Adobe Flash Player. The specific error occurs due to the way Adobe Flash handles the AMF0 response (_error) when connecting to a malicious RTMP server. By supplying a crafted AMF0 response it is possible to execute arbitrary code in the context of the vulnerable application. CVE-2012-0779 Exploits/Client Side Windows
11.30.2010 Adobe Flash Professional CS5 dwmapi DLL Hijacking Exploit Adobe Flash Professional CS5 is prone to a vulnerability that may allow execution of dwmapi.dll if this dll is located in the same folder than .FLA file. NOCVE-9999-45908 Exploits/Client Side Windows
11.29.2010 Adobe Illustrator CS4 aires DLL Hijacking Exploit Adobe Illustrator is prone to a vulnerability that may allow execution of aires.dll if this dll is located in the same folder than the .AIT file. NOCVE-9999-45895 Exploits/Client Side Windows
12.27.2009 Adobe Illustrator CS4 Encapsulated Postscript Buffer Overflow Exploit Adobe Illustrator is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Specifically, overly long DSC comments in Encapsulated PostScript .EPS files may corrupt memory. CVE-2009-4195 Exploits/Client Side Windows
12.13.2010 Adobe Illustrator CS5 dwmapi DLL Hijacking Exploit Adobe Illustrator CS5 is prone to a vulnerability that may allow the execution of any library file named dwmapi.dll, if this dll is located in the same folder than a .AIT file. CVE-2010-3152 Exploits/Client Side Windows
12.05.2010 Adobe InDesign CS4 dwmapi DLL Hijacking Exploit Adobe InDesign CS4 is prone to a vulnerability that may allow the execution of any library file named dwmapi.dll, if this dll is located in the same folder than a .INX file. NOCVE-9999-45904 Exploits/Client Side Windows
12.05.2010 Adobe LiveCycle Designer objectassisten_US DLL Hijacking Exploit Adobe LiveCycle Designer is prone to a vulnerability that may allow the execution of any library file named objectassisten_US.dll, if this dll is located in the same folder than a .TDS file. NOCVE-9999-45991 Exploits/Client Side Windows
11.06.2007 Adobe PageMaker Fontname exploit This module sends a mail with a specially crafted .pmd attachment. Once open, vulnerable versions of Adobe PageMaker will install an agent. CVE-2007-5169 Exploits/Client Side Windows
11.14.2007 Adobe PageMaker Fontname exploit update for IMPACT 7.5 This module sends a mail with a specially crafted .pmd attachment. Once open, vulnerable versions of Adobe PageMaker will install an agent. CVE-2007-5169 Exploits/Client Side Windows
05.04.2009 Adobe PDF CustomDictionaryOpen Buffer Overflow Exploit This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary errors in the customdictionaryopen() method in Javascript api. This can be exploited to cause a heap overflow when a specially crafted PDF file is opened. NOCVE-9999-38081 Exploits/Client Side Linux
08.24.2009 Adobe PDF CustomDictionaryOpen Buffer Overflow Update This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary errors in the customdictionaryopen() method in Javascript api. This can be exploited to cause a heap overflow when a specially crafted PDF file is opened. This update corrects the CVE number for this exploit. CVE-2009-1493 Exploits/Client Side Linux
10.18.2009 Adobe PDF FlateDecode Argument Buffer Overflow Exploit This module exploits a heap based buffer overflow vulnerability in Adobe Reader when handling a specially crafted PDF file. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. CVE-2009-3459 Exploits/Client Side Windows
03.29.2009 Adobe PDF getIcon Buffer Overflow Exploit This module exploits a stack based buffer overflow vulnerability in Adobe Reader when handling a specially crafted PDF file. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. CVE-2009-0927 Exploits/Client Side Windows
04.12.2009 Adobe PDF getIcon Buffer Overflow Exploit Update This module exploits a stack based buffer overflow vulnerability in Adobe Reader when handling a specially crafted PDF file. This update adds support for Adobe Acrobat Pro Extended 9. CVE-2009-0927 Exploits/Client Side Windows
03.05.2008 Adobe PDF JavaScript Buffer Overflow Exploit This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary error in collectEmailInfo() method in EScript.api. This can be exploited to cause a stack-based buffer overflow when a specially crafted PDF file is opened. CVE-2007-5659 Exploits/Client Side Windows
07.09.2008 Adobe PDF JavaScript Buffer Overflow Exploit Update This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary error in collectEmailInfo() method in EScript.api. This can be exploited to cause a stack-based buffer overflow when a specially crafted PDF file is opened. This update adds support for Adobe Reader 7.0.9. CVE-2007-5659 Exploits/Client Side Windows
07.13.2008 Adobe PDF JavaScript Buffer Overflow Exploit Update 2 This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary error in collectEmailInfo() method in EScript.api. This can be exploited to cause a stack-based buffer overflow when a specially crafted PDF file is opened. This update adds support for Windows XP SP3 and Windows Vista SP1. CVE-2007-5659 Exploits/Client Side Windows
09.11.2008 Adobe PDF JavaScript Buffer Overflow Exploit Update 3 This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary errors in collectEmailInfo() method in EScript.api. This can be exploited to cause a stack-based buffer overflow when a specially crafted PDF file is opened. This update adds support for Mac OS X 10.4.x and 10.5.x. CVE-2007-5659 Exploits/Client Side Windows, Mac OS X
12.15.2009 Adobe PDF Newplayer JavaScript Buffer Overflow Exploit This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary errors in newplayer() method in multimedia.api. This can be exploited to cause a buffer overflow when a specially crafted .PDF file is opened. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. CVE-2009-4324 Exploits/Client Side Windows
12.22.2009 Adobe PDF Newplayer JavaScript Buffer Overflow Exploit Update This module exploits a vulnerability in Adobe Reader and Adobe Acrobat Professional .PDF files. The vulnerability is caused due to boundary errors in newplayer() method in multimedia.api. This can be exploited to cause a buffer overflow when a specially crafted .PDF file is opened. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This Update adds support for Windows XP SP3 and Vista. CVE-2009-4324 Exploits/Client Side Windows
10.16.2007 Adobe PDF URI Handler Exploit This module exploits a vulnerability in Adobe Reader and Acrobat 8.0.1 and earlier on systems with Internet Explorer 7 installed. CVE-2007-5020 Exploits/Client Side Windows
11.16.2008 Adobe PDF URI Handler Exploit Update This module exploits a vulnerability in Adobe Reader and Acrobat 8.1.0 and earlier on systems with Internet Explorer 7 installed. This update adds support for WEB SERVER. CVE-2007-5020 Exploits/Client Side Windows
07.14.2008 Adobe Photoshop BMP Exploit This module exploits a vulnerability in Adobe Photoshop products when a malformed .BMP file is parsed. CVE-2008-1765 Exploits/Client Side Windows
06.06.2012 Adobe Photoshop Collada Asset Elements Buffer Overflow Exploit Adobe Photoshop CS5.1 is prone to a unicode overflow which occurs when overlong asset elements are processed. CVE-2012-2052 Exploits/Client Side Windows

Pages