CVE-2012-2289
EMC AppXtender WxSuperCtrl650.ocx ActiveX Control Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any location, and possibly execute arbitrary code, via unspecified vectors.
EMC ApplicationXtender Desktop anterior a v6.5 SP2 y ApplicationXtender Web Access .NET anterior a v6.5 SP2 permite a atacantes remotos subir ficheros a cualquier localización, y posiblemente ejecutar código arbitrario, a través de vectores no especificados.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC ApplicationXtender. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the WxSuperCtrl650.ocx ActiveX control. By manipulating a combination of the DisplayImageFile, AnnoLoad and AnnoSave methods, the vulnerable AnnoSave() method can enable an attacker to save arbitrary files inside arbitrary locations. The attacker is able to control the file extension and the creation path via a directory traversal issue. An attacker can leverage this vulnerability to execute code under the context of the process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-19 CVE Reserved
- 2012-08-25 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2012-08/0168.html | Mailing List | |
http://www.securitytracker.com/id?1027442 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Applicationxtender Desktop Search vendor "Emc" for product "Applicationxtender Desktop" | <= 6.5 Search vendor "Emc" for product "Applicationxtender Desktop" and version " <= 6.5" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Applicationxtender Web Access .net Search vendor "Emc" for product "Applicationxtender Web Access .net" | <= 6.5 Search vendor "Emc" for product "Applicationxtender Web Access .net" and version " <= 6.5" | - |
Affected
|