exploit-db-mirror/platforms/windows/dos/3419.txt
Offensive Security b3321b3426 DB: 2015-05-15
17 new exploits
2015-05-15 05:02:32 +00:00

24 lines
1.7 KiB
Text
Executable file

/*****************************************************************************\
* Microsoft Windows .doc File Malformed Pointers DoS *
* *
* *
* *
* Just move your mouse on the file and explorer crashes. If it does not try *
* to look at file properties. *
* Bug comes from Ole32.dll: *
* CMP DWORD PTR DS:[EAX+EBX],3 and we can set EAX, EDX and ESI with arbitrary *
* values. *
* *
* Check the file, magic offsets are *
* 4460 -> EDX *
* 4519 -> ESI *
* *
* *
* Successfully tested on Windows 2000 SP4 FR and XP SP2 FR. *
* *
* Coded by Marsu <MarsupilamiPowa@hotmail.fr> *
\*****************************************************************************/
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/3419.tar (03062007-Explorer_Crasher.tar)
# milw0rm.com [2007-03-06]