Wrote a new Metaspoit exploit module for the AOL Radio AmpX ActiveX control ConvertFile() stack-based buffer overflow vulnerability.
This module exploits a stack-based buffer overflow in AOL IWinAmpActiveX class (AmpX.dll) version 2.4.0.6 installed via AOL Radio website. By setting an overly long value to ‘ConvertFile()’, an attacker can overrun a buffer and execute arbitrary code.
This vulnerability was found by rgod and was published recently by Nine:Situations:Group. Still no patch from AOL, if you want to test it you can get the vulnerable package here on the AOL Radio web site.
Download aol_ampx_convertfile.rb.
Also on Metasploit.
References:
BID 35028
OSVDB 54706
milw0rm 8733
Categories: Exploits, Metasploit