CVE-2012-0292 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 7.09% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-03-08 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| symantec | altiris client management suite pcanywhere solution |
| symantec | altiris climentent manage suite pcanywhere solution |
| symantec | altiris deployment solution remote pcanywhere solution |
| symantec | altiris it management suite pcanywhere solution |
| symantec | pcanywhere |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | pcAnywhere 12.5.0 build 463 - Denial of Service | 2012-02-17 |
References
- http://secunia.com/advisories/48092
- http://www.exploit-db.com/exploits/18493/
- http://www.securityfocus.com/bid/52094
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120301_00
- http://secunia.com/advisories/48092
- http://www.exploit-db.com/exploits/18493/
- http://www.securityfocus.com/bid/52094
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120301_00
→ the Explorer · watch your stack · NVD