Buffer Overflow in Samsung iPOLiS Device Manager ActiveX Control
CVE-2015-0555

Currently unrated

Key Information:

Vendor

Samsung

Vendor
CVE Published:
24 February 2015

What is CVE-2015-0555?

A buffer overflow vulnerability exists in the XnsSdkDeviceIpInstaller.ocx ActiveX control utilized by Samsung iPOLiS Device Manager version 1.12.2. This flaw permits remote attackers to execute arbitrary code on the system by providing a long string in the first argument of the ReadConfigValue or WriteConfigValue functions. Exploitation of this vulnerability can lead to unauthorized actions and pose serious security risks to users of the affected product.

References

EPSS Score

24% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.