Lucene search

K
cveIcscertCVE-2012-3004
HistorySep 08, 2012 - 10:28 a.m.

CVE-2012-3004

2012-09-0810:28:20
icscert
web.nvd.nist.gov
24
cve-2012-3004
untrusted search path
vulnerabilities
realflex
realwin
flexview
gain privileges
local users
trojan horse
realwin.dll
keyhook.dll
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

25.6%

Multiple untrusted search path vulnerabilities in RealFlex RealWin before 2.1.13, FlexView before 3.1.86, and RealWinDemo before 2.1.13 allow local users to gain privileges via a Trojan horse (1) realwin.dll or (2) keyhook.dll file in the current working directory.

Affected configurations

Nvd
Node
realflexrealwinRange2.1.12
OR
realflexrealwinMatch1.06
OR
realflexrealwinMatch2.0
OR
realflexrealwinMatch2.1
Node
realflexflexviewRange3.1.85
Node
realflexrealwindemoRange2.1.12
VendorProductVersionCPE
realflexrealwin*cpe:2.3:a:realflex:realwin:*:*:*:*:*:*:*:*
realflexrealwin1.06cpe:2.3:a:realflex:realwin:1.06:*:*:*:*:*:*:*
realflexrealwin2.0cpe:2.3:a:realflex:realwin:2.0:*:*:*:*:*:*:*
realflexrealwin2.1cpe:2.3:a:realflex:realwin:2.1:*:*:*:*:*:*:*
realflexflexview*cpe:2.3:a:realflex:flexview:*:*:*:*:*:*:*:*
realflexrealwindemo*cpe:2.3:a:realflex:realwindemo:*:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

25.6%

Related for CVE-2012-3004