CVE-2012-0198 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 37.4% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 37.44% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-03-06 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | tivoli provisioning manager express for software distribution |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Tivoli Provisioning Manager Express for Software Distribution Isig.isigCtl.1 - ActiveX RunAndUploadFile() Method Overflow (Metasploit) | 2012-04-10 |
References
→ the Explorer · watch your stack · NVD