CVE-2012-5896
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 69%
from disclosure to weapon0 days
Published on NVDNov 17
1st PoCMar 28
metasploitMar 28
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized pointer."
Affected products
n/a · n/apublic PoCs found — 5✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/18735exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/18674cve_referencepacketstormsecurity.org/files/111312/Quest-InTrust-10.4.x-Annotation-Objects-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.org/files/111853/Quest-InTrust-Annotation-Objects-Uninitialized-Pointer.htmlunverifiedcve_referencewww.exploit-db.com/exploits/18674unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2012-03/0153.htmlhttp://dev.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/browser/intrust_annotatex_add.rbhttp://osvdb.org/80662http://packetstormsecurity.org/files/111312/Quest-InTrust-10.4.x-Annotation-Objects-Code-Execution.htmlhttp://packetstormsecurity.org/files/111853/Quest-InTrust-Annotation-Objects-Uninitialized-Pointer.htmlhttp://secunia.com/advisories/48566https://exchange.xforce.ibmcloud.com/vulnerabilities/74448http://www.exploit-db.com/exploits/18674http://www.securityfocus.com/bid/52765