This module exploits a vulnerability in the SQLDMO.DLL control included in the Microsoft SQL Server application. The exploit is triggered when the Start() method processes a long string argument resulting in a stack-based buffer overflow. This module runs a malicious web site on the Core Impact Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This module runs a web server waiting for vulnerable clients (Internet Explorer) to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
A remote code execution vulnerability exists in Microsoft Silverlight that can allow a specially crafted Silverlight application to access memory in an unsafe manner. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the current user. This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
This module exploits a stack-based buffer overflow in Microsoft PowerPoint Viewer 2003 by sending a specially crafted .PPT file with a malformed TextBytesAtom (0xF0A8) record. This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
This module exploits an error while processing the OEPlaceholderAtom Record when loading PPT files into memory that can be exploited to corrupt memory via a specially crafted PPT file. This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
A remote code execution vulnerability exists in the way that Microsoft Office Powerpoint handles specially crafted Powerpoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
A buffer overflow in Microsoft Outlook allows user-assisted remote attackers to execute arbitrary code via a crafted OSS file that triggers memory corruption.
This module exploits a vulnerability in the Microsoft Office Works converter that could allow remote code execution via a specially crafted .wps file.
Microsoft Office Word is prone to a memory corruption vulnerability when the wdGetApplicationObject function processes a malformed Word document. This can be exploited to execute arbitrary code by convincing an unsuspecting user to open a specially crafted .DOC file.
This module exploits a stack-based buffer overflow in Microsoft Office Word by sending a specially crafted .RTF file with a malformed pFragments record. This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
This module exploits a buffer overflow on Microsoft Office Word when parsing a malformed .DOC file with a specially crafted Property Data record.
Pagination
- Previous page
- Page 152
- Next page