9.3
CVSSv2

CVE-2012-0985

Published: 07/06/2012 Updated: 29/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.

Vulnerable Product Search on Vulmon Subscribe to Product

sony vaio pc wireless lan wizard 1.0

sony smartwi connection utillity 4.7.4

sony smartwi connection utillity 4.8

sony vaio wireless wizard 3.0

sony smartwi connection utillity 4.7

sony vaio easy connect 1.1.0

sony vaio wireless wizard 1.00

sony vaio wireless wizard 1.00_64

sony smartwi connection utillity 4.9

sony smartwi connection utillity 4.10

sony vaio wireless wizard 1.01

sony vaio wireless wizard 2.0

sony smartwi connection utillity 4.11

sony vaio easy connect 1.0.0

Exploits

Wireless Manager Sony VAIO version 4000 suffers from multiple buffer overflow vulnerabilities ...
Advisory ID: HTB23063 Product: Wireless Manager Sony VAIO Vendor: Sony Computers Vulnerable Version(s): 4000 and probably prior Tested Version: 4000 Vendor Notification: 7 December 2011 Vendor Patch: 20 January 2012 Public Disclosure: 30 May 2012 Vulnerability Type: Buffer Overflow CVE Reference: CVE-2012-0985 Solution Status: Fixed by Ven ...