peter bassill · operator
$ cve CVE-2012-2288 JSON

CVE-2012-2288 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 33.1% (pctl 98)

Patch early

A public exploit exists.

Description

Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS33.12% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2012-09-04
Last modified2026-06-16

Affected (1)

VendorProduct
emcnetworker

Public exploits

SourceTitleDate
exploit-dbEMC NetWorker - Format String (Metasploit)2012-11-07

References

→ the Explorer  ·  watch your stack  ·  NVD