CVE-2012-3796
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDJun 25
1st PoCMay 14
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/18878⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.org/adv/proservrex_1-adv.txthttp://ics-cert.us-cert.gov/advisories/ICSA-12-179-01http://secunia.com/advisories/49172https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txthttps://www.hmisource.com/otasuke/news/2012/0606.htmlhttp://www.securityfocus.com/bid/53499