CVE-2012-4334
published 2012-08-14CVE-2012-4334: The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote…
PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
6.75%
93.2th percentile
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | net-i_viewer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
10022F80 8B02 MOV EAX,DWORD PTR DS:[EDX]; 10022F82 8B4D E8 MOV ECX,DWORD PTR SS:[EBP-18]; 10022F85 FF10 CALL DWORD PTR DS:[EAX]
- →Detect instantiation of vulnerable ActiveX CLSIDs EEDBA32E-5C2D-48f1-A58E-0AAB0BC230E3 or 17A7F731-C9EC-461C-B813-2F42A1BB58EB (STWConfigNVR/STWConfig) followed by a call to the ConnectDDNS method, which triggers a virtual-call through a corrupted vtable pointer at offset 10022F85. ↗
- →Detect instantiation of ActiveX CLSIDs 3D6F2DBA-F4E5-40A6-8725-E99BC96CC23A or 208650B1-3CA1-4406-926D-45F2DBB9C299 followed by a call to BackupToAvi, indicating exploitation of the stack overflow variant. ↗
- →Monitor UDP traffic to ports 4505 (NiwMasterService) and 4508 (NiwStorageService) for packets with a negative/oversized 32-bit size field (e.g., 0x80808080), which triggers an endless loop DoS in the NET-i ware services. ↗
- →Flag network requests or file downloads for the known PoC archive netiware_1b.zip from aluigi.org, which contains exploit code for the ConnectDDNS and BackupToAvi vulnerabilities. ↗
- ·The ConnectDDNS code execution bug is acknowledged as low reliability by the researcher; detection may produce false negatives against real exploitation attempts. ↗
- ·No vendor patch was available at time of disclosure; affected systems running Samsung NET-i ware <= 1.37 on Windows remain permanently exposed unless the software is removed or network access is restricted. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/48965http://www.exploit-db.com/exploits/18765http://www.securityfocus.com/bid/53193https://exchange.xforce.ibmcloud.com/vulnerabilities/75069http://secunia.com/advisories/48965http://www.exploit-db.com/exploits/18765http://www.securityfocus.com/bid/53193https://exchange.xforce.ibmcloud.com/vulnerabilities/75069
2012-08-14
Published