PT-2012-5959 · Microsoft+1 · Windows+1

Publicado

2012-10-11

·

Atualizado

2013-03-02

·

CVE-2012-5377

CVSS v2.0

6.0

Média

VetorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ActivePerl version 5.16.1.1601
Description The issue concerns an untrusted search path vulnerability in the installation functionality. This vulnerability allows local users to gain privileges via a Trojan horse DLL in the C:PerlSitebin directory. The directory is added to the PATH system environment variable. A demonstration of this vulnerability involves a Trojan horse wlbsctrl.dll file used by the "IKE and AuthIP IPsec Keying Modules" system service in various Windows operating systems.
Recommendations For ActivePerl version 5.16.1.1601, consider removing the C:PerlSitebin directory from the PATH system environment variable to minimize the risk of exploitation. As a temporary workaround, restrict access to the C:PerlSitebin directory until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-5377

Produtos afetados

Activeperl
Windows