CVE-2012-2990
Published Aug 24, 2012
Last updated 12 years ago
Overview
- Description
- The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-94
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:samsung:kies:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6AC93228-11DF-48AE-A18A-9E8C705BE8DD", "versionEndIncluding": "2.3.2.12074" } ], "operator": "OR" } ] } ]