This module exploits a heap based buffer overflow vulnerability in the PrintControl module included in the Crystal Reports Viewer application. The exploit is triggered when the ServerResourceVersion property processes a crafted argument. This module runs a malicious web site on the Core Impact Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This module runs a web server waiting for vulnerable clients (Internet Explorer 6, 7, 8 and 9) to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
CVE Link
Exploit Platform
Exploit Type
Product Name