CVE-2012-2012
published 2012-06-29CVE-2012-2012: HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.36%
91.7th percentile
HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | system_management_homepage | <= 7.1.0-16 | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
ghsa4.3MEDIUM
vendor_redhat10.0CRITICAL
vendor_cisco3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Plone python code injection
ghsa·2022-05-17
CVE-2012-5495 [CRITICAL] CWE-94 Plone python code injection
Plone python code injection
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."
GHSA
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
ghsa·2022-05-17·CVSS 4.3
CVE-2013-1880 [MEDIUM] CWE-79 Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
GHSA
GHSA-pmxr-3vvf-xfm5: HP System Management Homepage (SMH) before 7
ghsa_unreviewed·2022-05-13
CVE-2012-2012 [HIGH] GHSA-pmxr-3vvf-xfm5: HP System Management Homepage (SMH) before 7
HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
GHSA
Jenkins allows Cross-Site Scripting (XSS)
ghsa·2022-05-04·CVSS 4.3
CVE-2012-0324 [MEDIUM] CWE-79 Jenkins allows Cross-Site Scripting (XSS)
Jenkins allows Cross-Site Scripting (XSS)
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0325.
Red Hat
JDK: java.lang.ClassLoder defineClass() code execution
vendor_redhat·2012-11-13·CVSS 9.3
CVE-2012-4823 [CRITICAL] JDK: java.lang.ClassLoder defineClass() code execution
JDK: java.lang.ClassLoder defineClass() code execution
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allows remote attackers to execute arbitrary code via vectors related to "insecure use of the java.lang.ClassLoder defineClass() method."
Red Hat
Django: Host header poisoning vulnerability
vendor_redhat·2012-10-17·CVSS 6.4
CVE-2012-4520 [MEDIUM] Django: Host header poisoning vulnerability
Django: Host header poisoning vulnerability
The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.
Package: Django (Red Hat Subscription Asset Manager) - Affected
Cisco
Cisco IOS SSL VPN Portal Page Denial of Service Vulnerability
vendor_cisco·2012-08-10·CVSS 3.5
CVE-2012-1344 [LOW] CWE-399 Cisco IOS SSL VPN Portal Page Denial of Service Vulnerability
Cisco IOS SSL VPN Portal Page Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on a targeted system.
The vulnerability is due to an unspecified issue that causes a device running the vulnerable software to reload when the web browser reloads the SSL VPN portal page. An authenticated, remote attacker could exploit this vulnerability by using a web browser to refresh the SSL VPN portal page to cause the device to reload, resulting in a DoS condition. A successful exploit could deny services for legitimate users.
Cisco has confirmed this vulnerability and has released updated software.
A successful exploit would require an attacker to authenticate to a targeted devic
Red Hat
Mozilla: Gecko memory corruption (MFSA 2012-44)
vendor_redhat·2012-07-17·CVSS 10.0
CVE-2012-1954 [CRITICAL] Mozilla: Gecko memory corruption (MFSA 2012-44)
Mozilla: Gecko memory corruption (MFSA 2012-44)
Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.
Red Hat
kernel: net: improve sequence number generation
vendor_redhat·2011-08-07·CVSS 9.1
CVE-2011-3188 [CRITICAL] kernel: net: improve sequence number generation
kernel: net: improve sequence number generation
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in
No detection rules found.
Exploit-DB
Java Applet - AverageRangeStatisticImpl Remote Code Execution (Metasploit)
exploitdb·2013-01-24·CVSS 9.8
CVE-2012-5076 [CRITICAL] Java Applet - AverageRangeStatisticImpl Remote Code Execution (Metasploit)
Java Applet - AverageRangeStatisticImpl Remote Code Execution (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
require 'rex'
class Metasploit3 false })
def initialize( info = {} )
super( update_info( info,
'Name' => 'Java Applet AverageRangeStatisticImpl Remote Code Execution',
'Description' => %q{
This module abuses the AverageRangeStatisticImpl from a Java Applet to run
arbitrary Java code outside of the sandbox, a different exploit vector than the one
exploited in the wild in November of 2012. The vulnerability affects Java version
7u7 and earlier.
},
'License'
Exploit-DB
WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
exploitdb·2012-06-06
CVE-2012-3574 WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
---
##################################################
# Description : Wordpress Plugins - MM Forms Community Arbitrary File
Upload Vulnerability
# Version : 2.2.5 - 2.2.6
# Link : http://wordpress.org/extend/plugins/mm-forms-community/
# Plugins : http://downloads.wordpress.org/plugin/mm-forms-community.zip
# Date : 24-05-2012
# Google Dork : inurl:/wp-content/plugins/mm-forms-community/
# Author : Sammy FORGIT - sam at opensyscom dot fr -
http://www.opensyscom.fr
##################################################
Exploit :
PostShell.php
"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>
Shell Access :
http://www.exemple.com/wordpress/
Exploit-DB
Microsoft Terminal Services - Use-After-Free (MS12-020)
exploitdb·2012-03-16
CVE-2012-0002 Microsoft Terminal Services - Use-After-Free (MS12-020)
Microsoft Terminal Services - Use-After-Free (MS12-020)
---
#######################################################################
Luigi Auriemma
Application: Microsoft Terminal Services / Remote Desktop Services
http://www.microsoft.com
http://msdn.microsoft.com/en-us/library/aa383015(v=vs.85).aspx
Versions: any Windows version before 13 Mar 2012
Platforms: Windows
Bug: use after free
Exploitation: remote, versus server
Date: 16 Mar 2012 (found 16 May 2011)
Author: Luigi Auriemma
e-mail: [email protected]
web: aluigi.org
Additional references:
http://www.zerodayinitiative.com/advisories/ZDI-12-044/
http://technet.microsoft.com/en-us/security/bulletin/ms12-020
#######################################################################
1) Introduction
2) Bug
3) The Code
4) Fix
##
Exploit-DB
PHPB2B 4.1 - 'q' Cross-Site Scripting
exploitdb·2011-01-01
CVE-2012-5099 PHPB2B 4.1 - 'q' Cross-Site Scripting
PHPB2B 4.1 - 'q' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/51221/info
PHPB2B is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/[patch]/list.php?do=search&q=[XSS]
Nuclei
Canon Devices - Authentication Bypass in Catwalk Server
nuclei·CVSS 7.5
CVE-2021-38154 [HIGH] Canon Devices - Authentication Bypass in Catwalk Server
Canon Devices - Authentication Bypass in Catwalk Server
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
Template:
id: CVE-2021-38154
info:
name: Canon Devices - Authentication Bypass in Catwalk Server
author: daffainfo
severity: high
description: |
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is
Bugzilla
CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes [epel-6]
bugzilla·2013-03-05·CVSS 7.5
CVE-2012-6135 [HIGH] CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes [epel-6]
CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodh
Bugzilla
CVE-2012-5510 kernel: xen: Grant table version switch list corruption vulnerability [fedora-all]
bugzilla·2012-12-03·CVSS 4.7
CVE-2012-5510 [MEDIUM] CVE-2012-5510 kernel: xen: Grant table version switch list corruption vulnerability [fedora-all]
CVE-2012-5510 kernel: xen: Grant table version switch list corruption vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2012-5120 CVE-2012-5128 v8: multiple flaws fixed in Google V8 3.13.7.5 (Chrome 23.0.1271.64) [fedora-all]
bugzilla·2012-11-08·CVSS 7.5
CVE-2012-5120 [HIGH] CVE-2012-5120 CVE-2012-5128 v8: multiple flaws fixed in Google V8 3.13.7.5 (Chrome 23.0.1271.64) [fedora-all]
CVE-2012-5120 CVE-2012-5128 v8: multiple flaws fixed in Google V8 3.13.7.5 (Chrome 23.0.1271.64) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2012-4564 libtiff: Missing return value check in ppm2tiff leading to heap-buffer overflow when reading a tiff file
bugzilla·2012-10-31·CVSS 6.8
CVE-2012-4564 [MEDIUM] CVE-2012-4564 libtiff: Missing return value check in ppm2tiff leading to heap-buffer overflow when reading a tiff file
CVE-2012-4564 libtiff: Missing return value check in ppm2tiff leading to heap-buffer overflow when reading a tiff file
A flaw was found in the way ppm2tiff, a tool to create a TIFF file from PPM, PGM and PBM image files, did not check the return value of TIFFScanlineSize() function. When TIFFScanlineSize encountered an integer-overflow and returned zero, this value was not checked. A remote attacker could provide a specially-crafted PPM image format file, that when processed by ppm2tiff would lead to ppm2tiff executable crash or, potentially, arbitrary code execution with the privileges of the user running the ppm2tiff binary.
Discussion:
Analysis (I am using libtiff-4.0.3 as the base for the line numbers):
In ppm2tiff.c:241 the following code is used:
buf = (unsigned char *)_TIFFmall
Bugzilla
CVE-2012-4460 qpid-cpp: lack of bounds checking in qpid::framing::Buffer can lead to DoS if asserts are enabled
bugzilla·2012-09-27·CVSS 5.0
CVE-2012-4460 [MEDIUM] CVE-2012-4460 qpid-cpp: lack of bounds checking in qpid::framing::Buffer can lead to DoS if asserts are enabled
CVE-2012-4460 qpid-cpp: lack of bounds checking in qpid::framing::Buffer can lead to DoS if asserts are enabled
The low-level serializing/deserializing methods (putOctet, getOctet and so on) in the qpid::framing::Buffer class do not perform bounds checks before the operation. Instead, there is an assert after the operation which fails on out-of-bounds access.
If asserts are enabled, this results in a pre-authentication denial-of-service vulnerability. Red Hat builds disable asserts, so they are not affected by this vulnerability. Examining the protocol decoders showed that the read overrun is limited to very few bytes because all the large types perform proper length checking (so it seems impossible that an unmapped page can be reached and cause a crash). Regarding write overruns, there
Bugzilla
CVE-2012-4412 glibc: strcoll() integer overflow leading to buffer overflow
bugzilla·2012-09-07·CVSS 7.5
CVE-2012-4412 [HIGH] CVE-2012-4412 glibc: strcoll() integer overflow leading to buffer overflow
CVE-2012-4412 glibc: strcoll() integer overflow leading to buffer overflow
An integer overflow, leading to buffer overflow flaw was found in the way the implementation of strcoll() routine, used to compare two strings based on the current locale, of glibc, the GNU libc libraries, performed calculation of memory requirements / allocation, needed for storage of the strings. If an application linked against glibc was missing an application-level sanity checks for validity of strcoll() arguments and accepted untrusted input, an attacker could use this flaw to cause the particular application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
Upstream bug report (including reproducer):
[1] http://sourceware.org/bugzilla/show_bug.cgi?id=14
Bugzilla
CVE-2012-3538 katello: pulp admin password logged in plaintext in world-readable katello/production.log
bugzilla·2012-08-27·CVSS 3.3
CVE-2012-3538 [LOW] CVE-2012-3538 katello: pulp admin password logged in plaintext in world-readable katello/production.log
CVE-2012-3538 katello: pulp admin password logged in plaintext in world-readable katello/production.log
James Laska ([email protected]) found the following vulnerability:
Description of problem:
The production.log is world readable ...
> # ll /var/log/katello/production.log
> -rw-r--r--. 1 katello katello 38128 Aug 27 13:56 /var/log/katello/production.log
While importing a manifest, I noticed the pulp admin password is available in plaintext in the production.log ...
> [DEBUG: 2012-08-27 13:20:08 #28453] Processing response: 200
> [DEBUG: 2012-08-27 13:20:08 #28453] Resource GET request: /pulp/api/users/admin/
> [DEBUG: 2012-08-27 13:20:08 #28453] Processing response: 200
> [DEBUG: 2012-08-27 13:20:08 #28453] Resource POST request: /pulp/api/users/, {"name":"hidden-HkmUvo","login":"hi
Bugzilla
CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability
bugzilla·2012-08-23·CVSS 4.7
CVE-2012-3496 [MEDIUM] CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability
CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability
XENMEM_populate_physmap can be called with invalid flags. By calling it with MEMF_populate_on_demand flag set, a BUG can be triggered if a translating paging mode is not being used.
A malicious guest kernel can crash the host.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue. Upstream acknowledges Matthew Daley as the original reporter.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
---
Now public via:
http://seclists.org/oss-sec/2012/q3/378
---
C
Bugzilla
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-16]
bugzilla·2012-06-06·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-16]
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=se
Bugzilla
CVE-2012-1568 kernel: execshield: predictable ascii armour base address [fedora-all]
bugzilla·2012-03-20·CVSS 1.9
CVE-2012-1568 [LOW] CVE-2012-1568 kernel: execshield: predictable ascii armour base address [fedora-all]
CVE-2012-1568 kernel: execshield: predictable ascii armour base address [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2012-1012 krb5: flaw in access control handling for strings in kadmin
bugzilla·2012-02-22·CVSS 5.5
CVE-2012-1012 [MEDIUM] CVE-2012-1012 krb5: flaw in access control handling for strings in kadmin
CVE-2012-1012 krb5: flaw in access control handling for strings in kadmin
It was reported [1] that, within the kadmin protocol, the access controls for get_strings/set_string were insufficient; anyone with global list privileges could get or modify string attributed on any principal.
It was also noted that the exposure depends on how generous the kadmind acl was with list permissions and whether or not string attributes were used in deployment (and noting that nothing in the core code uses them yet).
This has been fixed upstream [2] and in Fedora [3].
[1] http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&pass=guest&id=7093
[2] http://src.mit.edu/fisheye/changelog/krb5/?cs=25704
[3] http://koji.fedoraproject.org/koji/buildinfo?buildID=300840
Discussion:
This flaw was introduced
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Ciberamenazas
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities
Fortinet
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
blogs_fortinet·2017-09-05·CVSS 8.8
CVE-2012-0158 [HIGH] Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
FORTIGUARD LABS THREAT RESEARCH
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
By Jasper Manuel and Artem Semenchenko | September 05, 2017
Recently, FortiGuard Labs came across several malicious documents that exploit the vulnerability CVE-2012-0158. To evade suspicion from the victim, these RTF files drop decoy documents containing politically themed texts about a variety of Vietnamese government-related information. It was believed in a recent report that the hacking campaign where these documents were used was led by the Chinese hacking group 1937CN. The link to the group was found through malicious domains used as command and control servers by the attacker. In this blog, we will delve into the malware used in this campaign and will try to provide more clues as to
2012-06-29
Published