Stack-based Buffer Overflow in Samsung iPOLiS Device Manager ActiveX Control
CVE-2014-3912

Currently unrated

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 June 2014

Summary

A stack-based buffer overflow vulnerability exists in the FindConfigChildeKeyList method of the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control found in Samsung's iPOLiS Device Manager. This vulnerability allows remote attackers to execute arbitrary code by sending a specially crafted long value, potentially compromising the affected system without user intervention.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.