vendor:
iPOLiS Device Manager
by:
Praveen Darshanam
9.3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: iPOLiS Device Manager
Affected Version From: Samsung iPOLiS 1.12.2
Affected Version To: Samsung iPOLiS 1.12.2
Patch Exists: NO
Related CWE: CVE-2015-0555
CPE: a:samsung:ipolis_device_manager
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Ultimate N SP1
2015
(0day)Samsung iPOLiS XnsSdkDeviceIpInstaller ActiveX WriteConfigValue Remote Code Execution PoC (CVE-2015-0555)
A vulnerability exists in Samsung iPOLiS XnsSdkDeviceIpInstaller ActiveX, which could allow an attacker to execute arbitrary code on the vulnerable system. This is due to a stack-based buffer overflow in the WriteConfigValue() method of the XNSSDKDEVICELib.XnsSdkDevice ActiveX control (XnsSdkDeviceIpInstaller.ocx) when handling a long argument. An attacker can exploit this vulnerability by enticing a victim to visit a malicious web page containing a specially crafted HTML that would trigger the overflow.
Mitigation:
No known mitigation is available at this time.