cbcvebase.
CVE-2012-3809
published 2020-01-09

CVE-2012-3809: Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EXPLOIT
EPSS
4.99%
91.3th percentile
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

Affected

1 ranges
VendorProductVersion rangeFixed in
samsungkies< 2.5.0.12094_27_112.5.0.12094_27_11

Detection & IOCsextracted from sources · hover to see the quote

pathC:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\CmdAgent.dll
otherGUID: {1FA56F8D-A66E-4ABD-9BC9-6F61469E59AD} (CmdAgentLib)
otherGUID: {C668B648-A2BD-432C-854F-C8C0A275E1F1} (CommandAgent class)
commandDirCreate
commandDirDelete
  • Monitor for ActiveX instantiation of CmdAgentLib GUID {1FA56F8D-A66E-4ABD-9BC9-6F61469E59AD} from untrusted (browser/web) contexts, particularly calls to DirCreate or DirDelete methods via the ICommandAgent interface.
  • Alert on unexpected directory creation or deletion operations originating from CmdAgent.dll (Samsung Kies FirmwareUpdate component) in the path C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\.
  • Flag Samsung Kies versions prior to 2.5.0.12094_27_11 (e.g., 2.3.2.12054_20) as vulnerable; inventory and alert on presence of these versions in the environment.
  • ·The vulnerable ActiveX control (CmdAgent.dll / CmdAgentLib) exposes its ICommandAgent interface to untrusted sources without access control, meaning any web page can invoke directory modification methods if the control is installed and not kill-bitted.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.