Showing posts with label Samsung Kies. Show all posts
Showing posts with label Samsung Kies. Show all posts

Friday, January 11, 2013

HTB23136: Samsung Kies remote buffer overflow vulnerability

Samsung Kies 2.5.0.12114_1 remote buffer overflow vulnerability

Samsung Kies 2.5.0.12114_1 is vulnerable to remote buffer overflow vulnerability. Vulnerability has been discovered by High-Tech Bridge Security Research Lab and can be exploited to execute arbitrary code on vulnerable system.

Description of buffer overflow in Samsung Kies:
The vulnerability exists due to insufficient sanitisation of input data in the PrepareSync() method within the ActiveX control SyncService.dll, GUID {EA8A3985-F9DF-4652-A255-E4E7772AFCA8}, located by default in "C:\Program Files\Samsung\Kies\External\DeviceModules\SyncService.dll". A remote attacker can pass an arbitrary value to the "password" argument of the PrepareSync() method and trigger an ACCESS_VIOLATION exception, which could be exploited to successfully overwrite the EIP register and the SEH structure.

Details of Samsung KIES crash and Proof-of-concept (PoC) code is available on High-Tech Bridge website: Advisory HTB23136 - Remote Buffer Overflow Vulnerability in Samsung Kies.

Solution: Upgrade ro Samsung Kies version 2.5.1.12123_2_7.

Previously, High-Tech Bridge Security Research Lab had already discovered multiple vulnerabilities in Samsung Kies 2.3.2.12054_20.

Thursday, October 25, 2012

HTB23099: Samsung Kies multiple vulnerabilities

Multiple vulnerabilities in Samsung Kies version 2.3.2.12054_20 and probably prior have been discovered by High-Tech Bridge Security Research Lab, that allows remote attacker to compromise affected system, execute and modify arbitrary files, modify arbitrary directories and modify System Registry with privileges of the current user. Vulnerabilities types in HTB23099: NULL pointer dereference, improper access control vulnerabilities

  • Null Pointer Dereference in Samsung Kies:
    The vulnerability exists due to a null pointer dereference error in GetDataTable() method within the Samsung.DeviceService.DCA.DeviceDataParagonATGM.1 ActiveX control.

  • Arbitrary File Execution in Samsung Kies:
    The CmdAgent.dll library has numerous arbitrary file modification vulnerabilities present in "CmdAgentLib", in particular in the 'ICommandAgent' interface of the "CommandAgent" class. This default "ICommandAgent" interface has multiple functions and methods, and most of them can be leveraged by an untrusted source.

  • Arbitrary Directory Modification in Samsung Kies:
    The CmdAgent.dll library, has numerous arbitrary directory modification vulnerabilities present in "CmdAgentLib", in particular in the 'ICommandAgent' interface of the "CommandAgent" class. This default "ICommandAgent" interface has multiple functions and methods, and most of them can be leveraged by an untrusted source.

  • Arbitrary Registry Modification in Samsung Kies:
    The CmdAgent.dll library, has numerous Registry modification vulnerabilities present in "CmdAgentLib", in particular in the 'ICommandAgent' interface of the "CommandAgent" class. This default "ICommandAgent" interface has multiple functions and methods, and most of them can be leveraged by an untrusted source.

PoC-examples, additional details and how-to-fix information available on researcher's page.