peter bassill · operator
$ cve CVE-2012-0292 JSON

CVE-2012-0292 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS7.09% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2012-03-08
Last modified2026-06-16

Affected (5)

VendorProduct
symantecaltiris client management suite pcanywhere solution
symantecaltiris climentent manage suite pcanywhere solution
symantecaltiris deployment solution remote pcanywhere solution
symantecaltiris it management suite pcanywhere solution
symantecpcanywhere

Public exploits

SourceTitleDate
exploit-dbpcAnywhere 12.5.0 build 463 - Denial of Service2012-02-17

References

→ the Explorer  ·  watch your stack  ·  NVD