CVE-2007-5217
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 30%
from disclosure to weapon947 days
Published on NVDOct 5
1st PoC+947d
metasploitOct 3
exploitation probability
30%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16496unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/37785http://osvdb.org/38435http://secunia.com/advisories/26970http://secunia.com/advisories/26972https://exchange.xforce.ibmcloud.com/vulnerabilities/36929http://www.securityfocus.com/bid/25903http://www.vupen.com/english/advisories/2007/3335http://www.vupen.com/english/advisories/2007/3336