CVE-2012-3796

Pro-face Pro-Server EX < 1.30.000 & WinGP PC Runtime < 3.1.00 - Sensitive Info Exposure via Crafted Packet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-3796.

AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in Pro-face Pro-Server EX and WinGP PC Runtime, including memory corruption, integer overflow, and unhandled exceptions. The writeup provides disassembly snippets and explains the root causes but does not include functional exploit code.

Description

Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.

Exploits (1)

exploitdb WRITEUP
doswindows
https://www.exploit-db.com/exploits/18878

This is a detailed technical analysis of multiple vulnerabilities in Pro-face Pro-Server EX and WinGP PC Runtime, including memory corruption, integer overflow, and unhandled exceptions. The writeup provides disassembly snippets and explains the root causes but does not include functional exploit code.

Classification
Writeup 100%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Pro-face Pro-Server EX <= 1.30.000, WinGP PC Runtime <= 3.1.00
No auth needed
Prerequisites: Network access to the vulnerable service
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
https://www.hmisource.com/otasuke/news/2012/0606.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53499
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49172

Scores

EPSS 0.1090
EPSS Percentile 95.3%

Details

CWE
CWE-200
Status published
Products (5)
pro-face/pro-server_ex 1.21.000
pro-face/pro-server_ex 1.23.000
pro-face/pro-server_ex 1.24.200
pro-face/pro-server_ex < 1.30.000
pro-face/wingp_pc_runtime < 3.1.00
Published Jun 25, 2012
Tracked Since Feb 18, 2026