CVE-2012-2271

Skincrafter - Memory Corruption

Title source: rule
STIX 2.1

Description

Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to execute arbitrary code via a long string in the first argument (aka the reg_name argument).

Exploits (2)

exploitdb WORKING POC VERIFIED
by saurabh sharma · textlocalwindows
https://www.exploit-db.com/exploits/18892
exploitdb WORKING POC
by metacom · textremotewindows
https://www.exploit-db.com/exploits/35694

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/82086
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53611
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18892/

Scores

EPSS 0.4170
EPSS Percentile 97.4%

Details

CWE
CWE-119
Status published
Products (1)
skincrafter/skincrafter 3.0
Published May 21, 2012
Tracked Since Feb 18, 2026