CVE-2012-4333

Samsung Net-i Viewer - Memory Corruption

Title source: rule

Description

Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/19027
exploitdb WRITEUP VERIFIED
by Luigi Auriemma · textdoswindows
https://www.exploit-db.com/exploits/18765
metasploit WORKING POC NORMAL
by Luigi Auriemma, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/samsung_neti_wiewer_backuptoavi_bof.rb

Scores

EPSS 0.6943
EPSS Percentile 98.7%

Details

CWE
CWE-119
Status published
Products (1)
samsung/net-i_viewer 1.37.120316
Published Aug 14, 2012
Tracked Since Feb 18, 2026