← Vulnerability feed

Vulnerability record · CVE-2012-6275 · published 24 February 2013

CVE-2012-6275: BigAnt IM Message Server AntDS.exe stack buffer overflow

Bigantsoft · Bigant Im Message Server

AntDS.exe in BigAntSoft BigAnt IM Message Server contains multiple stack-based buffer overflows. A remote attacker can trigger them through the filename header of an SCH request or the userid component of a DUPF request, causing memory corruption with unspecified impact.

10.0 CVSS 2.0 High EPSS 46% · top 1.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityThe CVSS 2.0 base score is 10.0 with network reachability, no authentication and full impact, and EPSS is in the 98.7th percentile, so it warrants urgent attention despite the lack of KEV listing.

What it is

AntDS.exe in BigAntSoft BigAnt IM Message Server contains multiple stack-based buffer overflows. A remote attacker can trigger them through the filename header of an SCH request or the userid component of a DUPF request, causing memory corruption with unspecified impact.

Impact

Successful exploitation can corrupt stack memory and potentially allow remote code execution or a denial of service. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.

Attack surface

The flaw is network-reachable (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is indicated by the description or vector.

Exploitation

CVE-2012-6275 is not listed in CISA KEV and no public exploit or ransomware use is documented in the record. EPSS gives a 30-day exploitation probability of 0.46498 (98.764th percentile), indicating elevated predicted activity.

What to do

  • Apply the vendor patch or fixed build for BigAnt IM Message Server as soon as it is available.
  • If no patch exists, restrict network access to AntDS.exe and the IM service to trusted hosts only.
  • Place the IM server behind a firewall or segmentation boundary so it is not directly reachable from untrusted networks.
  • Monitor vendor and CERT/CC advisories for updated guidance and replacement versions.
  • Retire or isolate end-of-life BigAnt IM Message Server deployments that cannot be patched.

Detection

  • Inspect network traffic to the IM service for malformed SCH requests with oversized filename headers.
  • Inspect network traffic for DUPF requests containing oversized or malformed userid values.
  • Monitor AntDS.exe for crash events, access violations or unexpected process termination.
  • Review host logs for suspicious child processes or code execution originating from AntDS.exe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.kb.cert.org/vuls/id/990652 US Government Resource
http://www.kb.cert.org/vuls/id/990652 US Government Resource

Track CVE-2012-6275 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2012-6273Bigantsoft bigant im message server sql injection vulnerabilitySQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search u…EPSS 1.3%5.0CVE-2012-6274BigAnt IM Message Server unauthenticated file upload allows arbitrary file creationBigAntSoft BigAnt IM Message Server does not require authentication for file uploads, letting a remote attacker write arbitrary files into the AntSer…EPSS 47%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2012-6275), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.