CVE-2007-5217 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 30% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 29.99% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-10-05 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| altnet | altnet download manager |
| grokster | grokster |
| kazaa | kazaa media desktop |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Kazaa Altnet Download Manager - ActiveX Control Buffer Overflow (Metasploit) | 2010-05-09 |
References
- http://osvdb.org/37785
- http://osvdb.org/38435
- http://secunia.com/advisories/26970
- http://secunia.com/advisories/26972
- http://www.securityfocus.com/bid/25903
- http://www.vupen.com/english/advisories/2007/3335
- http://www.vupen.com/english/advisories/2007/3336
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36929
- http://osvdb.org/37785
- http://osvdb.org/38435
- http://secunia.com/advisories/26970
- http://secunia.com/advisories/26972
- http://www.securityfocus.com/bid/25903
- http://www.vupen.com/english/advisories/2007/3335
- http://www.vupen.com/english/advisories/2007/3336
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36929
→ the Explorer · watch your stack · NVD