[Originally posted on blog.c22.cc]
This video is a simple demonstration of the Metasploit ie_iepeers_pointer exploit on a fully patched Windows XP (sp3) system running IE 7.
Internet Explorer iepeers.dll use-after-free
CVE-2010-0806 / BID 38615 / KB981374
Code for this exploit was provided by Trancer.
More information about the exploit can be found on http://www.rec-sec.com
What is cool about this exploit is that it spawns a stable/new calc.exe and automatically migrates to its pid in one run. Add "run kitrap0d" for extra awesomeness and system privs :)
You need to be a member of Dissecting The Hack to add comments!
Join Dissecting The Hack