CORE IMPACT v7.5 - Exploits Update (Tue Jun 10 2008)
Creative Software AutoUpdate ActiveX Exploit
Exploits/Client Side [Windows]
Tue Jun 10 2008
This module exploits a vulnerability in the CTSUEng.ocx control included in the Creative Software AutoUpdate application. The exploit is triggered when the CacheFolder property processes a long string argument resulting in a stack-based buffer overflow. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site.
Exploits Vulnerabiltiy: CVE-2008-955











