CVE-2010-5299
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 34%
from disclosure to weapon0 days
Published on NVDMay 23
1st PoCAug 23
metasploitAug 23
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl file. NOTE: it has been reported that the overflow is in the lpFileName parameter of the CreateFileA function, but the overflow is probably caused by a separate, unnamed function.
Affected products
n/a · n/apublic PoCs found — 7
cve_referencepacketstormsecurity.com/files/125723/MicroP-0.1.1.1600-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/14720unverifiedcve_referencewww.exploit-db.com/exploits/17502unverifiedcve_referencewww.exploit-db.com/exploits/32261unverifiedexploitdbwww.exploit-db.com/exploits/32261unverifiedexploitdbwww.exploit-db.com/exploits/17502unverifiedexploitdbwww.exploit-db.com/exploits/14720unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/show/osvdb/73627http://packetstormsecurity.com/files/125723/MicroP-0.1.1.1600-Buffer-Overflow.htmlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/microp_mppl.rbhttp://www.exploit-db.com/exploits/14720http://www.exploit-db.com/exploits/17502http://www.exploit-db.com/exploits/32261