CVE-2012-2516 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 39.7% (pctl 99)
Patch early
A public exploit exists.
Description
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 39.71% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-07-05 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| ge | intelligent platforms proficy batch execution |
| ge | intelligent platforms proficy historian |
| ge | intelligent platforms proficy hmi\/scada ifix |
| ge | intelligent platforms proficy pulse |
| ge | intelligent platforms si7 i\/o driver |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KeyHelp - ActiveX LaunchTriPane Remote Code Execution (Metasploit) | 2012-10-11 |
References
- http://support.ge-ip.com/support/resources/sites/GE_FANUC_SUPPORT/content/live/KB/14000/KB14863/en_US/GEIP12-04%20Security%20Advisory%20-%20Proficy%20HTML%20Help.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-131-02.pdf
- http://support.ge-ip.com/support/resources/sites/GE_FANUC_SUPPORT/content/live/KB/14000/KB14863/en_US/GEIP12-04%20Security%20Advisory%20-%20Proficy%20HTML%20Help.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-131-02.pdf
→ the Explorer · watch your stack · NVD