8.5
CVSSv2

CVE-2007-3901

Published: 12/12/2007 Updated: 30/04/2019
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 860
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 up to and including 10.0 allows remote malicious users to execute arbitrary code via a crafted SAMI file.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft directx 5.2

microsoft directx 6.1

microsoft directx 8.1b

microsoft directx 8.2

microsoft directx 10.0

microsoft directx 8.1

microsoft directx 8.1a

microsoft directx 7.1

microsoft directx 8.0

microsoft directx 8.0a

microsoft directx 9.0c

microsoft directx 7.0

microsoft directx 7.0a

microsoft directx 9.0a

microsoft directx 9.0b

Exploits

Microsoft DirectX SAMI file parsing remote stack overflow exploit that binds a shell to port 4444 ...
#!/usr/bin/python ########################################################################## # Bug discovered by Jun Mao of VeriSign iDefense # wwwsecurityfocuscom/bid/26789 # CVE-2007-3901 # Coded by Matteo Memelli aka ryujin # wwwgray-worldnet wwwbe4mindcom # Tested on: Windows 2000 SP4 English, DirectX 70 (4070007 ...
## # $Id: ms07_064_samirb 10550 2010-10-05 01:05:49Z mc $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## class Metasploit3 < Msf::Ex ...