CVE-2012-5357 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 67.8% (pctl 99)
Patch early
A public exploit exists.
Description
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 67.78% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-19 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-10-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ektron | ektron content management system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ektron 8.02 - XSLT Transform Remote Code Execution (Metasploit) | 2012-12-05 |
References
- http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm
- https://technet.microsoft.com/library/security/msvr12-016
- https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/
- https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec
- http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htm
- https://technet.microsoft.com/library/security/msvr12-016
- https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/
- https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_exec
→ the Explorer · watch your stack · NVD