CVE-2009-1612

UnknownEPSS 33.26%

Last modified

CVE-2009-1612 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information. EPSS estimates a 33.26% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 3.09.04.17 and earlier are also affected.

Metrics

EPSS Probability
33.26%

98.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BaofengStorm2.7.9_8
BaofengStorm2.7.9_10
BaofengStorm2.8
BaofengStorm2.9
BaofengStorm3.9.3_25
BaofengStorm3.9.3_30
BaofengStorm3.9.4_17
BaofengStorm3.9.4_27

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-1612?
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 3.09.04.17 and earlier are also affected.
How severe is CVE-2009-1612?
Severity scoring for CVE-2009-1612 is pending analysis. The EPSS model estimates a 33.26% probability of exploitation in the next 30 days.
How do I fix CVE-2009-1612?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-1612?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST