Samsung iPOLiS Device Manager ActiveX Control Multiple Remote Code Execution Vulnerabilities
BID:67822
Info
Samsung iPOLiS Device Manager ActiveX Control Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 67822 |
| Class: | Unknown |
| CVE: |
CVE-2014-3911 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2014 12:00AM |
| Updated: | Aug 27 2014 12:23AM |
| Credit: | Ariele Caltabiano (kimiya) and Andrea Micalizzi (rgod). |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Samsung iPOLiS Device Manager ActiveX Control Multiple Remote Code Execution Vulnerabilities
Samsung iPOLiS Device Manager is prone to multiple remote code-execution vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Samsung iPOLiS Device Manager is prone to multiple remote code-execution vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Samsung iPOLiS Device Manager ActiveX Control Multiple Remote Code Execution Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Samsung iPOLiS Device Manager ActiveX Control Multiple Remote Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Samsung iPOLiS Device Manager ActiveX Control Multiple Remote Code Execution Vulnerabilities
References:
References: