9.3
CVSSv2

CVE-2008-0955

Published: 29/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote malicious users to execute arbitrary code via a long CacheFolder property value.

Vulnerable Product Search on Vulmon Subscribe to Product

creative creative software autoupdate engine

Exploits

<html> <!-- !!!NOT PRIVATE PLEASE DISTRIBUTE!!! Zer0Day Creative Software AutoUpdate Engine ActiveX Stack-Overflow (CacheFolder) Exploit by BitKrush <BitKrush +AT+ GMAILD0TC0M> +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ CacheFolder property is vulnerable to stack-based buffer overflow after 260 b ...
## # $Id: creative_software_cachefolderrb 9262 2010-05-09 17:45:00Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf ...