CORE IMPACT v7 - Exploits Update (Thu Sep 27 2007)
IE TLIApplication Exploit
Exploits/Client Side [Windows]
Thu Sep 27 2007
This module runs a web server waiting for vulnerable clients (Internet Explorer) to connect to it. When the client connects, it will try to install an agent by instancing TLBINF32.DLL (sometimes installed as VSTLBINF.DLL) with a malicious DLL (IMPActiveX.ocx) as parameter. IMPActiveX.ocx has a helpstringdll property pointing to itself, and implements DLLGetDocumentation to install an agent.
Exploits Vulnerabiltiy: CVE-2007-2216











