[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MS Windows GDI (EMR_COLORMATCHTOTARGETW) Exploit MS08-021

Author
Ac!dDrop
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9271
Category
remote exploits
Date add
01-10-2008
Platform
unsorted
=========================================================
MS Windows GDI (EMR_COLORMATCHTOTARGETW) Exploit MS08-021
=========================================================

EMR_COLORMATCHTOTARGETW stack buffer overflow exploit
By Ac!dDrop

This is one of the 2 Vulnerabilities of MS08-021

Tested on Windows xp professional SP1
GDi32.dll    5.1.2600.1106
kernel32.dll 5.1.2600.1106
ws2_32.dll   5.1.2600.0

calc.zip---> executes calculator
IE.zip and localhost.zip ------>  connects at localhost at port 230


On Windows Xp Sp2 only causes Denial of service.
 -(Vulnerable function guarded with a GS cookie)
 -(The function which copies data to stack has an exception handler which recovers from access violations so u cant exploit it by hitting next page ).

http://inj3ct0r.com/sploits/9271.tgz




#  0day.today [2024-11-16]  #