CORE Impact Pro Exploits and Security Updates
When you buy CORE Impact Pro, we provide real-time updates including new penetration testing exploits and tests for additional platforms as they become available. We advise you of any new modules by email, after which you can download them directly from within CORE Impact Pro. All product updates are free during the license period. You're always on the cutting edge of vulnerability and threat intelligence because CORE Impact Pro keeps you there.
Use the controls below to navigate CORE Impact exploits and other modules.
|
Released Date |
Title | Description | Vulnerabilty | Category | Platform |
|---|---|---|---|---|---|
| 06.18.2013 | Mozilla Firefox plugin objects Privileged Code Execution Exploit | This module exploits a remote code injection in Mozilla Firefox by using vulnerabilities CVE-2013-0758 and CVE-2013-0757. | CVE-2013-0758 | Exploits/Client Side | Windows |
| 06.18.2013 | Microsoft Internet Explorer COALineDashStyleArray Integer Overflow Exploit (MS13-037) | This module exploits an integer overflow vulnerability in the Vector Markup Language (VML) on Internet Explorer. The vulnerability exists in the handling of the dashstyle.array length for VML shapes on the vgx.dll module. This vulnerability was one of the 2013's Pwn2Own challenges. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. | CVE-2013-2551 | Exploits/Client Side | Windows |
| 06.18.2013 | Microsoft Office PNG File Buffer Overflow Exploit | Buffer overflow in Microsoft Office allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation. | CVE-2013-1331 | Exploits/Client Side | Windows |
| 06.17.2013 | Zoom Player BMP File Processing Buffer Overflow Exploit | Zoom Player is prone to a buffer-overflow via a specially crafted BMP image with an overly large "biClrUsed" value. | CVE-2013-3259 | Exploits/Client Side | Windows |
| 06.16.2013 | XnView XCF Processing Image Layer Buffer Overflow Exploit | Xnview is prone to a stack based buffer overflow which can be exploited through a specially crafted image layer within an XCF file. | CVE-2013-3246 | Exploits/Client Side | Windows |
| 06.14.2013 | Sketchup MAC Pict Material Palette Stack Corruption Exploit | Sketchup fails to validate the input when parsing an embedded MAC Pict texture, leading to an arbitrary stack offset overwrite and finally to an arbitrary code execution. | CVE-2013-3664 | Exploits/Client Side | Windows |
| 06.13.2013 | Artweaver JPG Image Processing Buffer Overflow Exploit | The vulnerability is caused due to a boundary error when processing JPG image files and can be exploited to cause a stack-based buffer overflow via a specially crafted JPG image file. | CVE-2013-3481 | Exploits/Client Side | Windows |
| 06.11.2013 | IntraSrv Simple Web Server Buffer Overflow Exploit | IntraSrv is prone to a buffer overflow within GET requests with an overly long HOST parameter. | NOCVE-9999-58319 | Exploits/Remote | Windows |
| 06.11.2013 | Microsoft Windows Win32k pprFlattenRec Vulnerability Exploit | This module exploits a vulnerability in win32k.sys when the EPATHOBJ::pprFlattenRec() doesn't initialize the pointer to the next memory chunk. | CVE-2013-3660 | Exploits/Local | Windows |
| 06.10.2013 | Oracle Java Driver Manager Remote Code Execution Exploit | This module exploits a vulnerability in Oracle Java taking advantages of the java.sql.DriverManager class. The specific flaw exists within the usage of java.sql.DriverManager. The issue lies in an implicit call to toString() that is made within a doPrivileged block. This flaw allows an unprivileged Java applet to escape the sandbox and execute arbitrary code on the target machine with the privileges of the current user. This vulnerability was one of the 2013's Pwn2Own challenges. | CVE-2013-1488 | Exploits/Client Side | Windows, Linux, Mac OS X |
| 06.09.2013 | MongoDB nativeHelper Remote Code Execution Exploit | This module exploits a vulnerability in MongoDB server. An arbitrary value passed as a parameter to the nativeHelper function in MongoDB server allows an attacker to control the execution flows to achieve remote code execution. | CVE-2013-1892 | Exploits/Remote | Linux |
| 06.05.2013 | Serva TFTPD Service Large Read Requests Parsing DoS | The Serva32 TFTPD service is vulnerable to a buffer overflow vulnerability when parsing large read requests. When the application reads in a large buffer the application crashes. | CVE-2013-0145 | Denial of Service/Remote | Windows |
| 06.05.2013 | Wordpress W3 Total Cache PHP Remote Code Execution Exploit | This module exploits a vulnerability in W3 Total Cache plugin for Wordpress. Certain macros such as mfunc allow to inject PHP code into comments. By injecting a crafted comment into a valid post an attacker can execute arbitrary PHP code on systems running vulnerable installations of W3 Total Cache. | CVE-2013-2010 | Exploits/Remote | Linux |
| 06.03.2013 | HP Intelligent Management FaultDownloadServlet Directory Traversal Exploit | This module exploits a directory traversal vulnerability in HP Intelligent Management Center. Due to a lack of authentication and a directory traversal vulnerability in the FaultDownloadServlet component, an attacker can retrieve arbitrary files. | CVE-2012-5202 | Exploits/Remote File Disclosure | Windows |
| 06.03.2013 | HP Intelligent Management IctDownloadServlet Directory Traversal Exploit | This module exploits a directory traversal vulnerability in HP Intelligent Management Center. Due to a lack of authentication and a directory traversal vulnerability in the IctDownloadServlet component, an attacker can retrieve arbitrary files. | CVE-2012-5204 | Exploits/Remote File Disclosure | Windows |
| 06.03.2013 | Apple Mac OS X DirectoryService AllocFromProxyStruct Buffer Underflow DoS | This module exploits a vulnerability in the Mac OS X DirectoryService by sending a specially crafted packet to the 625/TCP port. | CVE-2013-0984 | Denial of Service/Remote | Mac OS X |
| 05.31.2013 | Symantec AMS Intel Handler Service DoS | This module exploits a vulnerability in Symantec AMS Intel Handler service by sending a malformed packet to the 38292/TCP port to crash the application. | CVE-2010-3268 | Denial of Service/Remote | Windows |
| 05.31.2013 | IBM SPSS SamplePower Vsflex8l ActiveX Control Buffer Overflow Exploit | Buffer overflow when a special malformed string is assigned to the ComboList or ColComboList property. The code looks for a '#'in the string then copies into a global buffer in the data section with a static size of 0x64. | CVE-2012-5945 | Exploits/Client Side | Windows |
| 05.29.2013 | Novell ZENworks Mobile Management Remote Code Execution Exploit | This module exploits a vulnerability in the Novell ZENworks Mobile Management application by injecting code in the PHP session file and leveraging a Local File Inclusion in mdm.php to execute the injected PHP code. | CVE-2013-1081 | Exploits/Remote | Windows |
| 05.29.2013 | IBM SPSS SamplePower C1sizer ActiveX Control Buffer Overflow Exploit | A vulnerability when handling the TabCaption buffer, C1sizer.ocx does not properly check the size before running lstrcatA and therefore will cause a buffer overflow. | CVE-2012-5946 | Exploits/Client Side | Windows |
| 05.29.2013 | Keylogger Update 2 | This update resolves an issue while trying to run the "Keylogger" module. | Exploits/Remote | ||
| 05.26.2013 | Oracle Java Font Handling Remote Code Execution Exploit | A specific flaw exists within the handling of CFF-based OpenType fonts. The issue lies in two operators that allow for reading and writing elements beyond the allocated buffers. An attacker can leverage this vulnerability to execute code under the context of the current process. | CVE-2013-1491 | Exploits/Client Side | Windows |
| 05.22.2013 | SAP Netweaver Message Server _MsJ2EE_AddStatistics Memory Corruption Exploit | The Message Server component of SAP Netweaver is prone to a memory corruption vulnerability when the _MsJ2EE_AddStatistics function handles a specially crafted request with iflag value 0x0c MS_J2EE_SEND_TO_CLUSTERID, or 0x0d MS_J2EE_SEND_BROADCAST. This vulnerability can be exploited by remote unauthenticated attackers to execute arbitrary code on the vulnerable server. | CVE-2013-1592 | Exploits/Remote | Windows |
| 05.21.2013 | Microsoft Windows Win32k Buffer Overflow Exploit (MS13-046) | This module exploits a vulnerability in Windows kernel calling to "DisplayConfigGetDeviceInfo" function with crafted parameters. | CVE-2013-1333 | Exploits/Local | Windows |
| 05.20.2013 | Supported services list update | This package updates the list of network service TCP and UDP ports known to the Impact exploits framework. | Exploits/Remote | ||
| 05.20.2013 | EMC AlphaStor Library Control Program Buffer Overflow Exploit | The vulnerability is caused due to an error in the AlphaStor Library Control Program when processing commands and can be exploited to cause a buffer overflow. | CVE-2013-0946 | Exploits/Remote | Windows |
| 05.20.2013 | Wireshark DRDA Dissector DoS | The DRDA protocol dissector in Wireshark can enter an infinite loop when processing an specially crafted DRDA packet with the iLength field set to 0, causing Wireshark to stop responding. | CVE-2012-3548 | Denial of Service/Remote | Windows, Linux |
| 05.17.2013 | Light HTTP Daemon Buffer Overflow Exploit | Light HTTPD is prone to a buffer overflow when handling specially crafted GET request packets. | NOCVE-9999-57945 | Exploits/Remote | Windows |
| 05.17.2013 | PHPMyAdmin Replace Table Prefix Remote Code Execution Exploit | This module abuses a vulnerability in phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 that allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature. | CVE-2013-3238 | Exploits/Remote | Linux |
| 05.16.2013 | Microsoft Windows Win32k Divide Error Exception DoS (MS13-046) | This module exploits a Windows kernel vulnerability calling to "NtGdiScaleViewportExtEx" function by using crafted parameters. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation. | CVE-2013-1334 | Denial of Service/Local | Windows |
