CVE-2012-0985: Buffer Overflow
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.0064, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0985?
CVE-2012-0985 is classified as a high severity vulnerability due to its potential for buffer overflow exploits.
How do I fix CVE-2012-0985?
To fix CVE-2012-0985, update affected software to the latest version provided by Sony that addresses the buffer overflow issues.
Which software is affected by CVE-2012-0985?
CVE-2012-0985 affects multiple Sony products including SmartWi Connection Utility and VAIO Wireless Wizard among others.
What are the risks associated with CVE-2012-0985?
The risks associated with CVE-2012-0985 include potential remote code execution and unauthorized access impacting system integrity.
Is exploitation of CVE-2012-0985 easy to accomplish?
Exploitation of CVE-2012-0985 could be relatively easy for an attacker with knowledge of the vulnerable software and the right exploit available.