Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-6332 PoC — Windows OLE 自动化数组远程执行代码漏洞

Source
Associated Vulnerability
Title:Windows OLE 自动化数组远程执行代码漏洞 (CVE-2014-6332)
Description:OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
Description
 app 	turn nil publics and privates into blanks 	3 months ago 	config 	Use bundler/setup for more graceful bundler related failures 	11 days ago 	data 	Add token fiddling from nishang 	12 hours ago 	db 	Revert "Diff triggering comment" 	12 days ago 	documentation 	Switch to Msf::OperatingSystems::Match::WINDOWS 	2 months ago 	external 	Use PDWORD_PTR and DWORD_PTR 	29 days ago 	features 	Up aruba timeout for simplecov overhead 	4 days ago 	lib 	Check for load errors in reload_all 	4 days ago 	modules 	Land #4255 - CVE-2014-6332 Internet Explorer 	19 hours ago 	plugins 	Land #3588, @tobd-r7's Fix SpaceBeforeModifierKeyword Rubocop warning 	4 months ago 	script 	rails generate cucumber:install 	3 months ago 	scripts 	delete the old script 	a month ago 	spec 	Remove debug file writes 	2 days ago 	test 	Fix up comment splats with the correct URI 	a month ago 	tools 	Fix bugs 	24 days ago 	.gitignore 	Add note about rbenv for rvm .versions.conf local override 	24 days ago 	.gitmodules 	Add RDI submodule, port Kitrap0d 	a year ago 	.mailmap 	Add @trosen-r7's alias for commits 	6 months ago 	.rspec 	Add modern --require to .rspec 	2 months ago 	.rubocop.yml 	Reapply PR #4113 (removed via #4175) 	18 days ago 	.ruby-gemset 	Restoring ruby and gemset files 	6 months ago 	.ruby-version 	Oh good, another Ruby version bump 	14 days ago 	.simplecov 	Remove fastlib 	2 months ago 	.travis.yml 	Enable fast_finish on travis-ci 	12 days ago 	.yardopts 	Various merge resolutions from master <- staging 	4 months ago 	CONTRIBUTING.md 	Add a don't to CONTRIBUTING about merge messages 	11 days ago 	COPYING 	With 66 days left in 2014, may as well update 	a month ago 	Gemfile 	metasploit-credential bump to 0.13.3 	16 days ago 	Gemfile.local.example 	Various merge resolutions from master <- staging 	4 months ago 	Gemfile.lock 	Bump mdm version number 	12 days ago 	HACKING 	Update link for The Metasploit Development Environment 	5 months ago 	LICENSE 	Remove fastlib 	2 months ago 	README.md 	Encourage use of the installer for users. 	8 months ago 	Rakefile 	Merge branch 'feature/MSP-11130/metasploit-framework-spec-constants' … 	24 days ago 	metasploit-framework-db.gemspec 	metasploit-credential bump to 0.13.3 	16 days ago 	metasploit-framework-full.gemspec 	Update metasploit-framework-full.gemspec 	23 days ago 	metasploit-framework-pcap.gemspec 	Depend on metasloit-framework in optional gemspecs 	24 days ago 	metasploit-framework.gemspec 	Update meterpreter_bins to 0.0.11 	18 days ago 	msfbinscan 	Remove fastlib 	2 months ago 	msfcli 	Fix thread-leaks in msfcli spec 	17 days ago 	msfconsole 	@wvu-r7 is a skilled negotiator. s/stdout/stderr/ 	a month ago 	msfd 	Remove fastlib 	2 months ago 	msfelfscan 	Remove fastlib 	2 months ago 	msfencode 	Remove fastlib 	2 months ago 	msfmachscan 	Remove fastlib 	2 months ago 	msfpayload 	fixes merge conflicts msfpayload & exe 	a month ago 	msfpescan 	Remove fastlib 	2 months ago 	msfrop 	Remove fastlib 	2 months ago 	msfrpc 	Remove fastlib 	2 months ago 	msfrpcd 	Remove call to legacy db.sink queue, closes #4244 	7 days ago 	msfupdate 	Always use maybe_wait_and_exit in msfupdate 	a year ago 	msfvenom 	Fix #4047 - undefined method `rank' due to an invalid encoder name 	19 days ago README.md 
File Snapshot

[4.0K] /data/pocs/b69142f097efd39266f68d92f68612642e68a5d7 0 directories, 0 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →