cbcvebase.
CVE-2012-3808
published 2020-01-09

CVE-2012-3808: Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.

PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EXPLOIT
EPSS
4.99%
91.2th percentile
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.

Affected

1 ranges
VendorProductVersion rangeFixed in
samsungkies< 2.5.0.12094_27_112.5.0.12094_27_11

Detection & IOCsextracted from sources · hover to see the quote

pathC:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\CmdAgent.dll
otherGUID:{1FA56F8D-A66E-4ABD-9BC9-6F61469E59AD}
otherGUID:{C668B648-A2BD-432C-854F-C8C0A275E1F1}
registryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\FRoGito
pathC:\Program Files(x86)\Samsung\Kies\External\DeviceModules\DCAPARAGONGM.dll
otherGUID:{7650BC47-036D-4D5B-95B4-9D622C8D00A4}
  • Monitor for ActiveX instantiation of CLSID {1FA56F8D-A66E-4ABD-9BC9-6F61469E59AD} (CmdAgentLib) or {C668B648-A2BD-432C-854F-C8C0A275E1F1} (CommandAgent) from untrusted web content, as these expose arbitrary file copy/move/delete methods.
  • Alert on calls to FileCopy, FileCopySync, FileDelete, FileMove, or FileMoveSync methods via the ICommandAgent ActiveX interface, especially targeting sensitive paths such as %SystemRoot%\System32\drivers\etc\hosts.
  • Detect registry key creation/deletion under HKCU\Software\Microsoft\Windows\CurrentVersion by CmdAgent.dll or its host process, which may indicate exploitation of the RegiCreateKey/RegiDeleteKey methods.
  • Flag presence of CmdAgent.dll loaded within a browser process (e.g., iexplore.exe), as exploitation occurs via ActiveX from a web page.
  • ·CVE-2012-3808 specifically covers the Arbitrary File Modification vulnerability; the same CmdAgent.dll / CmdAgentLib ActiveX control is also responsible for CVE-2012-3807 (file execution), CVE-2012-3809 (directory modification), and CVE-2012-3810 (registry modification). IOCs for the shared DLL/GUIDs apply to all four CVEs.
  • ·Vulnerable version is 2.3.2.12054_20 and probably prior; the fix is version 2.5.0.12094_27_11. Detections should be scoped to Samsung Kies installations older than the fixed version.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.