Immunity, Inc.
Name wp_quicktime_punk
CVE 2010-1818
Exploit Pack White_Phosphorus
DescriptionApple Quicktime <=v7.6.7 _Marshaled_pUnk Vulnerability
NotesVENDOR: Apple
Notes:
This is a client-side exploit - so use it via clientd or httpserver.
If you choose to host the exploit file on an independandant webserver, then you must include the .dll file as well.

VersionsAffected: Quicktime Versions 7.6.6, 7.6.7 IE Versions 6/7/8
Repeatability: Unlimited
References: http://reversemode.com/index.php?option=com_content&task=view&id=69&Itemid=1
http://zerodayinitiative.com/advisories/ZDI-10-168/
CVE Url: http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1818
Date public: 2010-08-30
CVE: 2010-1818
CVSS: 9.3

Learn more about the CANVAS Exploit Pack here: White_Phosphorus