cbcvebase.
CVE-2012-4333
published 2012-08-14

CVE-2012-4333: Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i…

PriorityP263critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
60.45%
99.0th percentile
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.

Affected

1 ranges
VendorProductVersion rangeFixed in
samsungnet-i_viewer

Detection & IOCsextracted from sources · hover to see the quote

otherCLSID: 3D6F2DBA-F4E5-40A6-8725-E99BC96CC23A
otherCLSID: 208650B1-3CA1-4406-926D-45F2DBB9C299
otherCLSID: EEDBA32E-5C2D-48f1-A58E-0AAB0BC230E3
otherCLSID: 17A7F731-C9EC-461C-B813-2F42A1BB58EB
filenameCNC_Ctrl.dll
commandtarget1.BackupToAvi(0, 0, 0, unescape("#{bof}"));
port4505
port4508
  • Detect instantiation of the vulnerable ActiveX CLSIDs (3D6F2DBA-F4E5-40A6-8725-E99BC96CC23A or 208650B1-3CA1-4406-926D-45F2DBB9C299) in HTML/script content, particularly combined with a call to BackupToAvi with a long fname parameter.
  • Monitor for heap-spray pattern using 0x0c0c0c0c return address and large unescape() blobs of \x0c bytes in JavaScript delivered via browser, consistent with the Metasploit exploit module targeting IE 6/7 on Windows XP SP3.
  • Alert on network traffic to UDP ports 4505 and 4508 containing oversized or malformed size fields (negative 32-bit values) targeting NiwMasterService and NiwStorageService respectively.
  • Detect presence of CNC_Ctrl.dll (version 1.5.1.1) on Windows hosts as an indicator of the vulnerable Samsung NET-i viewer 1.37 installation.
  • The exploit uses 'migrate -f' as InitialAutoRunScript; post-exploitation process migration activity following iexplore.exe may indicate successful exploitation.
  • ·The ConnectDDNS bug (CLSIDs EEDBA32E and 17A7F731) is noted as unreliable to replicate and was not fully researched; detection confidence for that vector is lower.
  • ·Payload bad characters are restricted to null bytes only; any detection based on shellcode patterns must account for null-free shellcode.
  • ·No vendor fix was available at time of disclosure; patching is not an available mitigation.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.