Posted by Trancer on Jul 28 2009

AwingSoftHere’s a new Metaspoit exploit module I wrote for the AwingSoft Web3D Player SceneURL() stack-based buffer overflow vulnerability.

This module exploits a stack-based buffer overflow within Winds3D Viewer of AwingSoft Awakening 3.0 (WindsPly.ocx v3.5.0.0). This ActiveX is a plugin of AwingSoft Web3D Player. By setting an overly long value to ‘SceneURL()’, an attacker can overrun a buffer and execute arbitrary code.

This vulnerability was found by shinnai and was published recently on milw0rm and shinnai web site.

Download awingsoft_web3d_bof.rb.
Also on Metasploit.

References:
OSVDB 60017

Enjoy.

Categories: Exploits, Metasploit

Leave a Reply


Follow Recognize-Security on Twitter