Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-0292

Severity
5.0MEDIUM
EPSS
2.1%
top 15.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 8
Latest updateMay 4

Description

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-444q-7pcf-frfw: The awhost32 service in Symantec pcAnywhere through 122022-05-04
CVEList
CVE-2012-0292: The awhost32 service in Symantec pcAnywhere through 122012-03-08

💥Exploits & PoCs

1
Exploit-DB
pcAnywhere 12.5.0 build 463 - Denial of Service2012-02-17
CVE-2012-0292 (MEDIUM CVSS 5) | The awhost32 service in Symantec pc | cvebase.io