CVE-2012-2990

CWE-94Code Injection3 documents3 sources
Severity
9.3CRITICAL
EPSS
1.6%
top 18.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 24
Latest updateMay 17

Description

The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDsamsung/kies2.3.2.12074

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6ff5-xppw-fx3m: The MASetupCaller ActiveX control before 12022-05-17
CVEList
CVE-2012-2990: The MASetupCaller ActiveX control before 12012-08-24
CVE-2012-2990 (CRITICAL CVSS 9.3) | The MASetupCaller ActiveX control b | cvebase.io