CVE-2013-7246
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 11%
from disclosure to weapon0 days
Published on NVDJan 30
1st PoCJan 24
VulnCheckJan 30
exploitation probability
11%top 4% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute arbitrary code via a long string, as exploited in the wild in January 2014.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/124886unverifiedcve_referencewww.exploit-db.com/exploits/31179unverifiedexploitdbwww.exploit-db.com/exploits/31179unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://blog.spiderlabs.com/2014/01/daumgame-activex-0day.htmlhttp://packetstormsecurity.com/files/124886http://seclists.org/fulldisclosure/2014/Jan/132https://exchange.xforce.ibmcloud.com/vulnerabilities/90588https://www.trustwave.com/spiderlabs/advisories/TWSL2014-002.txthttp://www.exploit-db.com/exploits/31179