Here’s a new Metaspoit exploit module I wrote for the AwingSoft Web3D Player SceneURL() stack-based buffer overflow vulnerability.
This module exploits a stack-based buffer overflow within Winds3D Viewer of AwingSoft Awakening 3.0 (WindsPly.ocx v3.5.0.0). This ActiveX is a plugin of AwingSoft Web3D Player. By setting an overly long value to ‘SceneURL()’, an attacker can overrun a buffer and execute arbitrary code.
This vulnerability was found by shinnai and was published recently on milw0rm and shinnai web site.
Download awingsoft_web3d_bof.rb.
Also on Metasploit.
References:
OSVDB 60017
Enjoy.
Categories: Exploits, Metasploit