CVE-2012-2990: Code Injection
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.120741313, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2990?
CVE-2012-2990 is considered a high severity vulnerability due to its potential for allowing remote code execution.
How do I fix CVE-2012-2990?
To fix CVE-2012-2990, upgrade to a version of Samsung KIES that is later than 2.3.2.12074.
What impact does CVE-2012-2990 have on my system?
CVE-2012-2990 allows remote attackers to download and execute arbitrary programs on affected systems.
Which versions of Samsung KIES are affected by CVE-2012-2990?
CVE-2012-2990 affects Samsung KIES versions prior to 2.3.2.12074.
Is CVE-2012-2990 a local or remote vulnerability?
CVE-2012-2990 is a remote vulnerability, which can be exploited over the network.