CVE-2012-0985

Sony VAIO PC Wireless LAN Wizard 1.0-4.11 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0985. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates a buffer overflow vulnerability in Sony VAIO Wireless Manager via crafted HTML/JS that triggers unsafe methods in WifiMan.dll. It crashes the application by passing oversized strings to SetTmpProfileOption() or ConnectToNetwork().

Description

Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.

Exploits (1)

exploitdb WORKING POC
by High-Tech Bridge SA · htmldoswindows
https://www.exploit-db.com/exploits/18958

The exploit demonstrates a buffer overflow vulnerability in Sony VAIO Wireless Manager via crafted HTML/JS that triggers unsafe methods in WifiMan.dll. It crashes the application by passing oversized strings to SetTmpProfileOption() or ConnectToNetwork().

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Sony VAIO Wireless Manager 4.0.0.0
No auth needed
Prerequisites: Victim must visit a malicious webpage · Sony VAIO Wireless Manager 4.0.0.0 or prior installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-05/0147.html
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18958
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49340
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/82401
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53735
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75978

Scores

EPSS 0.1298
EPSS Percentile 95.8%

Details

CWE
CWE-119
Status published
Products (14)
sony/smartwi_connection_utillity 4.7
sony/smartwi_connection_utillity 4.7.4
sony/smartwi_connection_utillity 4.8
sony/smartwi_connection_utillity 4.9
sony/smartwi_connection_utillity 4.10
sony/smartwi_connection_utillity 4.11
sony/vaio_easy_connect 1.0.0
sony/vaio_easy_connect 1.1.0
sony/vaio_pc_wireless_lan_wizard 1.0
sony/vaio_wireless_wizard 1.00
... and 4 more
Published Jun 07, 2012
Tracked Since Feb 18, 2026