CVE-2008-1605 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.9% — more likely to be exploited than 79% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-04-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| leadtools | multimedia toolkit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | LeadTools MultiMedia 15 - 'LTMM15.dll' ActiveX Control Arbitrary File Overwrite | 2008-03-25 |
References
- http://secunia.com/advisories/29538
- http://www.securityfocus.com/bid/28442
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1206434746.ff.php&page=last
- http://www.shinnai.altervista.org/xplits/TXT_lyyELAFI8pOPu2p7N6cq.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41467
- http://secunia.com/advisories/29538
- http://www.securityfocus.com/bid/28442
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1206434746.ff.php&page=last
- http://www.shinnai.altervista.org/xplits/TXT_lyyELAFI8pOPu2p7N6cq.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41467
→ the Explorer · watch your stack · NVD