Lucene search

K
zdiPeter VreugdenhilZDI-07-012
HistoryApr 03, 2007 - 12:00 a.m.

Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow Vulnerability

2007-04-0300:00:00
Peter Vreugdenhil
www.zerodayinitiative.com
17

EPSS

0.672

Percentile

98.0%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Yahoo Messenger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists within the ActiveX control Yahoo.AudioConf: DLL: yacscom.dllCLSID: 2B323CD9-50E3-11D3-9466-00A0C9700498 When large values are specified for the ‘socksHostname’ and ‘hostname’ properties, and the createAndJoinConference() method is called, a stack overflow occurs. Exploitation can result in code execution under the context of the current user.