Samsung Kies SyncService ActiveX PrepareSync() Buffer Overflow

critical Nessus Plugin ID 63686

Synopsis

The remote host has software installed that is affected by a buffer overflow vulnerability.

Description

According to the version of Samsung Kies SyncService ActiveX installed on the remote host, the 'PrepareSync()' method is affected by a buffer overflow vulnerability.

A remote attacker could use this vulnerability to cause a denial of service or potentially execute arbitrary code.

Solution

Upgrade to Samsung Kies 2.5.1.12123_2_7 or later.

See Also

https://www.htbridge.com/advisory/HTB23136

Plugin Details

Severity: Critical

ID: 63686

File Name: samsung_kies_preparesync_activex_bof.nasl

Version: 1.5

Type: local

Agent: windows

Family: Windows

Published: 1/24/2013

Updated: 12/4/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2012-6429

Vulnerability Information

CPE: cpe:/a:samsung:kies

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/27/2012

Vulnerability Publication Date: 1/9/2013

Reference Information

CVE: CVE-2012-6429

BID: 57249