Vulnerability record · CVE-2012-4333 · published 14 August 2012
CVE-2012-4333: Samsung NET-i viewer ActiveX BackupToAvi stack buffer overflow
Samsung · Net I Viewer
The UMS_Ctrl and UMS_Ctrl_STW ActiveX controls in Samsung NET-i viewer 1.37.120316 contain multiple stack-based buffer overflows in the BackupToAvi method. A long string in the fname parameter overflows a stack buffer, allowing remote code execution. The flaw matters because the affected control is reachable from a browser and public exploit code exists.
Description
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is a remotely reachable, unauthenticated code execution issue with public exploit code and very high EPSS, though it is not in KEV and affects an old, likely limited-deployment product.
What it is
The UMS_Ctrl and UMS_Ctrl_STW ActiveX controls in Samsung NET-i viewer 1.37.120316 contain multiple stack-based buffer overflows in the BackupToAvi method. A long string in the fname parameter overflows a stack buffer, allowing remote code execution. The flaw matters because the affected control is reachable from a browser and public exploit code exists.
Impact
An attacker can execute arbitrary code in the context of the process hosting the ActiveX control, typically the victim's browser or viewer application, giving full control of the user's session.
Attack surface
Reached over the network via a crafted web page or document that instantiates the vulnerable ActiveX control and passes an oversized fname value to BackupToAvi. No authentication is required, but the victim must load the malicious content in a browser that permits the control to run.
Exploitation
Public exploit code is referenced on Exploit-DB and SecurityFocus, and EPSS is 0.59567 (99th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Apply the vendor fix or upgrade NET-i viewer and the UMS_Ctrl/UMS_Ctrl_STW controls to a non-vulnerable version; if no patch is available, remove or disable the affected ActiveX controls.
- Restrict or block the vulnerable CLSIDs in Internet Explorer via kill-bit settings and enterprise browser policy.
- Disable ActiveX execution in browsers used to access untrusted sites, and enforce a strict allowlist of permitted controls.
- Segment or restrict network access to systems running NET-i viewer so only trusted management hosts can reach them.
- Monitor vendor advisories for updated guidance, since the record does not list fixed versions.
Detection
- Search endpoint inventories and registry for the UMS_Ctrl 1.5.1.1 and UMS_Ctrl_STW 2.0.1.0 CLSIDs and for NET-i viewer 1.37.120316 installations.
- Monitor browser and viewer process crashes or anomalous child processes spawned from iexplore.exe or the NET-i viewer executable.
- Alert on network requests or referrers delivering pages that instantiate the vulnerable ActiveX controls, and on known exploit URLs from Exploit-DB or SecurityFocus.
- Review proxy and IDS logs for exploit delivery patterns targeting the BackupToAvi method or oversized fname parameters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4333 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.