Vulnerability record · CVE-2012-6275 · published 24 February 2013
CVE-2012-6275: BigAnt IM Message Server AntDS.exe stack buffer overflow
Bigantsoft · Bigant Im Message Server
AntDS.exe in BigAntSoft BigAnt IM Message Server contains multiple stack-based buffer overflows. A remote attacker can trigger them through the filename header of an SCH request or the userid component of a DUPF request, causing memory corruption with unspecified impact.
Description
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe CVSS 2.0 base score is 10.0 with network reachability, no authentication and full impact, and EPSS is in the 98.7th percentile, so it warrants urgent attention despite the lack of KEV listing.
What it is
AntDS.exe in BigAntSoft BigAnt IM Message Server contains multiple stack-based buffer overflows. A remote attacker can trigger them through the filename header of an SCH request or the userid component of a DUPF request, causing memory corruption with unspecified impact.
Impact
Successful exploitation can corrupt stack memory and potentially allow remote code execution or a denial of service. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
The flaw is network-reachable (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is indicated by the description or vector.
Exploitation
CVE-2012-6275 is not listed in CISA KEV and no public exploit or ransomware use is documented in the record. EPSS gives a 30-day exploitation probability of 0.46498 (98.764th percentile), indicating elevated predicted activity.
What to do
- Apply the vendor patch or fixed build for BigAnt IM Message Server as soon as it is available.
- If no patch exists, restrict network access to AntDS.exe and the IM service to trusted hosts only.
- Place the IM server behind a firewall or segmentation boundary so it is not directly reachable from untrusted networks.
- Monitor vendor and CERT/CC advisories for updated guidance and replacement versions.
- Retire or isolate end-of-life BigAnt IM Message Server deployments that cannot be patched.
Detection
- Inspect network traffic to the IM service for malformed SCH requests with oversized filename headers.
- Inspect network traffic for DUPF requests containing oversized or malformed userid values.
- Monitor AntDS.exe for crash events, access violations or unexpected process termination.
- Review host logs for suspicious child processes or code execution originating from AntDS.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.kb.cert.org/vuls/id/990652 | US Government Resource |
| http://www.kb.cert.org/vuls/id/990652 | US Government Resource |
Track CVE-2012-6275 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-6275), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.