PT-2012-6178 · Quest · Quest Intrust

Rgod

·

Published

2012-11-17

·

Updated

2017-09-02

·

CVE-2012-5897

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Quest InTrust versions 10.4.0.853 and earlier
Description The issue concerns the improper implementation of the SaveToFile method in the SimpleTree and ReportTree classes within the ARDoc ActiveX control. This allows remote attackers to write or overwrite arbitrary files using the bstrFileName argument.
Recommendations For Quest InTrust versions 10.4.0.853 and earlier, consider restricting access to the SaveToFile method in the SimpleTree and ReportTree classes until a patch is available. As a temporary workaround, avoid using the bstrFileName argument in the affected method to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5897

Affected Products

Quest Intrust