peter bassill · operator
$ cve CVE-2012-5897 JSON

CVE-2012-5897 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 3.8% (pctl 90)

Patch early

A public exploit exists.

Description

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS3.83% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2012-11-17
Last modified2026-06-16

Affected (1)

VendorProduct
questintrust

Public exploits

SourceTitleDate
exploit-dbQuest InTrust 10.4.x - ReportTree / SimpleTree Classes2012-03-28

References

→ the Explorer  ·  watch your stack  ·  NVD