Samsung Kies < 2.5.0.12094_27_11 Multiple ActiveX Control Vulnerabilities

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The remote host has ActiveX controls that are affected by multiple
vulnerabilities.

Description :

The version of Samsung Kies ActiveX controls installed on the remote
host is affected by multiple vulnerabilities :

- A vulnerability in GetDataTable() method in
'DCAPARAGONGM.dll' is affected by a NULL pointer
dereference that could be used to perform a denial of
service of the program. (CVE-2012-3806)

- Multiple vulnerabilities exist affecting CmdAgentLib in
'CmdAgent.dll'. An attacker may be able to exploit this
issue to gain elevated privileges. (CVE-2012-3807,
CVE-2012-3808 CVE-2012-3809, CVE-2012-3810)

See also :

https://www.htbridge.com/advisory/HTB23099

Solution :

Upgrade to Samsung Kies 2.5.0.12094_27_11 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 65612 ()

Bugtraq ID: 55936

CVE ID: CVE-2012-3806
CVE-2012-3807
CVE-2012-3808
CVE-2012-3809
CVE-2012-3810

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now