Lucene search

K
cve[email protected]CVE-2012-5896
HistoryNov 17, 2012 - 9:55 p.m.

CVE-2012-5896

2012-11-1721:55:04
web.nvd.nist.gov
20
cve-2012-5896
annotation objects
activex control
quest intrust
remote code execution
vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.661 Medium

EPSS

Percentile

97.9%

The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an “uninitialized pointer.”

Affected configurations

NVD
Node
questintrustRange10.4.0.853
OR
questintrustMatch10.1
OR
questintrustMatch10.2.5
OR
questintrustMatch10.3
OR
questintrustMatch10.4

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.661 Medium

EPSS

Percentile

97.9%

Related for CVE-2012-5896