cbcvebase.
CVE-2012-4956
published 2012-11-18

CVE-2012-4956: Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements…

PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
37.72%
98.4th percentile
Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

Affected

1 ranges
VendorProductVersion rangeFixed in
novellfile_reporter

Detection & IOCsextracted from sources · hover to see the quote

filenameNFRAgent.exe
processNFRAgent.exe
  • Detect exploitation attempts by monitoring HTTP requests containing an 'SRS' record name with a large number of 'VOL' elements directed at NFRAgent.exe
  • Alert on processes spawned by or anomalous memory activity within NFRAgent.exe, particularly heap corruption indicators consistent with a large number of VOL elements in an SRS record
  • ·Vulnerability is confirmed present in NFR Agent version 1.0.4.3 (File Reporter 1.0.2); testing scope may not cover other versions
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.