Wrote a new Metaspoit exploit module for the Autodesk IDrop ActiveX control heap-based memory corruption vulnerability.
This module exploits a heap-based memory corruption vulnerability in Autodesk IDrop ActiveX control (IDrop.ocx) version 17.1.51.160. An attacker can execute arbitrary code by triggering a heap use after free condition using the Src, Background, PackageXml properties.
This vulnerability was found by Elazar Board and apparently Autodesk is not going to fix this issue… Better flip on the killbit for this one.
Download autodesk_idrop.rb.
Also on Metasploit.
References:
BID 34352
OSVDB 53265
milw0rm 8560
Categories: Exploits, Metasploit