Here’s a proof-of-concept exploit for Microsoft Internet Explorer Object Clone Deletion Memory Corruption vulnerability in case you don’t use the Metasploit Framework and still want to test it.
Like the Metasploit module I wrote for it, it has been tested successfully on Windows XP SP3, Windows Vista SP1 and Windows Server 2003 SP2 (no 961260 patch).
Update: also tested successfully on Windows Server 2008 with no DEP (OptOut – iexplorer.exe).
Download ms09-002.html.
Enjoy it.
Categories: Exploits