CVE-2012-3809
published 2020-01-09CVE-2012-3809: Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EXPLOIT
EPSS
4.99%
91.3th percentile
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | kies | < 2.5.0.12094_27_11 | 2.5.0.12094_27_11 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for ActiveX instantiation of CmdAgentLib GUID {1FA56F8D-A66E-4ABD-9BC9-6F61469E59AD} from untrusted (browser/web) contexts, particularly calls to DirCreate or DirDelete methods via the ICommandAgent interface. ↗
- →Alert on unexpected directory creation or deletion operations originating from CmdAgent.dll (Samsung Kies FirmwareUpdate component) in the path C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\. ↗
- →Flag Samsung Kies versions prior to 2.5.0.12094_27_11 (e.g., 2.3.2.12054_20) as vulnerable; inventory and alert on presence of these versions in the environment. ↗
- ·The vulnerable ActiveX control (CmdAgent.dll / CmdAgentLib) exposes its ICommandAgent interface to untrusted sources without access control, meaning any web page can invoke directory modification methods if the control is installed and not kill-bitted. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
2020-01-09
Published