Vulnerability record · CVE-2007-5779 · published 1 November 2007
CVE-2007-5779: GOM Player GomWeb ActiveX control buffer overflow via OpenUrl
Gom Player · Gom Player
The GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 shipped with Gretech GOM Player 2.1.6.3499 contains a buffer overflow reachable through a long argument to the OpenUrl method. A remote attacker can trigger memory corruption that may lead to arbitrary code execution in the context of the user running the player. The record is old and thin, but the flaw is a classic unauthenticated network-reachable memory corruption issue.
Description
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated memory corruption with public exploit code and a very high EPSS score, though it requires an outdated ActiveX control and likely user interaction.
What it is
The GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 shipped with Gretech GOM Player 2.1.6.3499 contains a buffer overflow reachable through a long argument to the OpenUrl method. A remote attacker can trigger memory corruption that may lead to arbitrary code execution in the context of the user running the player. The record is old and thin, but the flaw is a classic unauthenticated network-reachable memory corruption issue.
Impact
An attacker who can get the vulnerable control invoked gains the ability to corrupt memory and potentially execute arbitrary code with the privileges of the logged-on user. That could allow installation of malware, data theft or full host compromise.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication required. Because it is an ActiveX control, exploitation typically requires the victim to load a malicious web page or document that instantiates the control, so some user interaction is likely despite the vector.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.715 probability, 99.4th percentile) and a public Exploit-DB entry (4579) exists, indicating exploit code is available. No ransomware usage is documented.
What to do
- Upgrade GOM Player to a version later than 2.1.6.3499 that no longer ships the vulnerable GomWeb3.dll control, or remove the product if it is no longer needed.
- Disable or kill the GomManager/GomWeb Control ActiveX object in Internet Explorer and other browsers via the kill-bit mechanism.
- Restrict browser and email clients from instantiating unsigned or untrusted ActiveX controls, and block the GomWeb3.dll CLSID where possible.
- Apply network and endpoint controls to prevent users from reaching untrusted sites that host the exploit, and keep legacy IE/ActiveX environments off the network.
- If the control must remain, isolate GOM Player usage to low-privilege, non-sensitive accounts and hosts.
Detection
- Search endpoint inventories for GomWeb3.dll version 1.0.0.12 and for the GomManager/GomWeb Control ActiveX registration.
- Monitor for browser or application processes loading GomWeb3.dll and for crashes in GOM Player or IE that correlate with the control.
- Hunt for network requests to known exploit hosts or pages referencing the OpenUrl method and the GomWeb3 control.
- Review proxy and DNS logs for access to sites hosting Exploit-DB 4579 or similar GOM Player ActiveX exploit pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5779 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5779), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.