cbcvebase.
CVE-2012-4334
published 2012-08-14

CVE-2012-4334: The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote…

PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
6.75%
93.2th percentile
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.

Affected

1 ranges
VendorProductVersion rangeFixed in
samsungnet-i_viewer

Detection & IOCsextracted from sources · hover to see the quote

otherEEDBA32E-5C2D-48f1-A58E-0AAB0BC230E3
other17A7F731-C9EC-461C-B813-2F42A1BB58EB
other3D6F2DBA-F4E5-40A6-8725-E99BC96CC23A
other208650B1-3CA1-4406-926D-45F2DBB9C299
port4505
port4508
urlhttp://aluigi.org/poc/netiware_1b.zip
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18112.zip
commandudpsz -b 0x80 -T SERVER 4505 0x28
commandudpsz -T -c "REM" 0 -C 80808080 0x10 SERVER 4508 0x14
bytes
10022F80 8B02 MOV EAX,DWORD PTR DS:[EDX]; 10022F82 8B4D E8 MOV ECX,DWORD PTR SS:[EBP-18]; 10022F85 FF10 CALL DWORD PTR DS:[EAX]
  • Detect instantiation of vulnerable ActiveX CLSIDs EEDBA32E-5C2D-48f1-A58E-0AAB0BC230E3 or 17A7F731-C9EC-461C-B813-2F42A1BB58EB (STWConfigNVR/STWConfig) followed by a call to the ConnectDDNS method, which triggers a virtual-call through a corrupted vtable pointer at offset 10022F85.
  • Detect instantiation of ActiveX CLSIDs 3D6F2DBA-F4E5-40A6-8725-E99BC96CC23A or 208650B1-3CA1-4406-926D-45F2DBB9C299 followed by a call to BackupToAvi, indicating exploitation of the stack overflow variant.
  • Monitor UDP traffic to ports 4505 (NiwMasterService) and 4508 (NiwStorageService) for packets with a negative/oversized 32-bit size field (e.g., 0x80808080), which triggers an endless loop DoS in the NET-i ware services.
  • Flag network requests or file downloads for the known PoC archive netiware_1b.zip from aluigi.org, which contains exploit code for the ConnectDDNS and BackupToAvi vulnerabilities.
  • ·The ConnectDDNS code execution bug is acknowledged as low reliability by the researcher; detection may produce false negatives against real exploitation attempts.
  • ·No vendor patch was available at time of disclosure; affected systems running Samsung NET-i ware <= 1.37 on Windows remain permanently exposed unless the software is removed or network access is restricted.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.