CVE-2012-0985

Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
sonysmartwi_connection_utillity
4.7
sonysmartwi_connection_utillity
4.7.4
sonysmartwi_connection_utillity
4.8
sonysmartwi_connection_utillity
4.9
sonysmartwi_connection_utillity
4.10
sonysmartwi_connection_utillity
4.11
sonyvaio_easy_connect
1.0.0
sonyvaio_easy_connect
1.1.0
sonyvaio_pc_wireless_lan_wizard
1.0
sonyvaio_wireless_wizard
1.00
sonyvaio_wireless_wizard
1.00_64:_64
sonyvaio_wireless_wizard
1.01
sonyvaio_wireless_wizard
2.0
sonyvaio_wireless_wizard
3.0
𝑥
= Vulnerable software versions