CVE-2012-5896
CVE-2012-5896
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized pointer."
Productos afectados
n/a · n/aPoCs públicas encontradas — 5
cve_referencepacketstormsecurity.org/files/111312/Quest-InTrust-10.4.x-Annotation-Objects-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.org/files/111853/Quest-InTrust-Annotation-Objects-Uninitialized-Pointer.htmlno verificadocve_referencewww.exploit-db.com/exploits/18674no verificadoexploitdbwww.exploit-db.com/exploits/18735no verificadoexploitdbwww.exploit-db.com/exploits/18674no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://archives.neohapsis.com/archives/bugtraq/2012-03/0153.htmlhttp://dev.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/browser/intrust_annotatex_add.rbhttp://osvdb.org/80662http://packetstormsecurity.org/files/111312/Quest-InTrust-10.4.x-Annotation-Objects-Code-Execution.htmlhttp://packetstormsecurity.org/files/111853/Quest-InTrust-Annotation-Objects-Uninitialized-Pointer.htmlhttp://secunia.com/advisories/48566https://exchange.xforce.ibmcloud.com/vulnerabilities/74448http://www.exploit-db.com/exploits/18674http://www.securityfocus.com/bid/52765