CVE-2012-4956
published 2012-11-18CVE-2012-4956: Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements…
PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
37.72%
98.4th percentile
Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | file_reporter | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring HTTP requests containing an 'SRS' record name with a large number of 'VOL' elements directed at NFRAgent.exe ↗
- →Alert on processes spawned by or anomalous memory activity within NFRAgent.exe, particularly heap corruption indicators consistent with a large number of VOL elements in an SRS record ↗
- ·Vulnerability is confirmed present in NFR Agent version 1.0.4.3 (File Reporter 1.0.2); testing scope may not cover other versions ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/87574http://www.kb.cert.org/vuls/id/273371https://community.rapid7.com/community/metasploit/blog/2012/11/16/nfr-agent-buffer-vulnerabilites-cve-2012-4959http://osvdb.org/87574http://www.kb.cert.org/vuls/id/273371https://community.rapid7.com/community/metasploit/blog/2012/11/16/nfr-agent-buffer-vulnerabilites-cve-2012-4959
2012-11-18
Published