CVE-2012-2024
published 2012-05-09CVE-2012-2024: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.38%
91.7th percentile
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator | — | — |
| adobe | illustrator_cs5.5 | <= 15 | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_11_version_24h2 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
cisa8.8HIGH
vendor_msrc9.8CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-38p9-j94m-w67p: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-0780 [CRITICAL] CWE-119 GHSA-38p9-j94m-w67p: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2024 [CRITICAL] CWE-119 GHSA-mqr5-ffq5-hrp4: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-c895-43rw-5x9c: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2025 [CRITICAL] CWE-119 GHSA-c895-43rw-5x9c: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
GHSA
GHSA-5c6j-76f2-jq69: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2023 [CRITICAL] CWE-119 GHSA-5c6j-76f2-jq69: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
GHSA
GHSA-3wqx-wh6r-cf85: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2026 [CRITICAL] CWE-119 GHSA-3wqx-wh6r-cf85: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.
GHSA
GHSA-cgw2-g5cm-vwm6: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-2042 [CRITICAL] CWE-119 GHSA-cgw2-g5cm-vwm6: Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
CISA
Microsoft Internet Explorer Use-After-Free Vulnerability
cisa·2024-07-23·CVSS 8.8
CVE-2012-4792 [HIGH] CWE-416 Microsoft Internet Explorer Use-After-Free Vulnerability
Vulnerability: Microsoft Internet Explorer Use-After-Free Vulnerability
Affected: Microsoft Internet Explorer
Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://learn.microsoft.com/en-us/lifecycle/products/internet-explorer-11; https://nvd.nist.gov/vuln/detail/CVE-2012-4792
Remediation Due Date: 2024-08-13
Suricata
ET WEB_SERVER PHP.//Input in HTTP POST
suricata·2014-11-25
CVE-2012-1823 ET WEB_SERVER PHP.//Input in HTTP POST
ET WEB_SERVER PHP.//Input in HTTP POST
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER PHP.//Input in HTTP POST"; flow:established,to_server; http.method; content:"POST"; http.uri.raw; content:"php|3a 2f 2f|input"; fast_pattern; http.request_body; content:"<?"; startswith; reference:url,www.deependresearch.org/2014/07/another-linux-ddos-bot-via-cve-2012-1823.html; classtype:trojan-activity; sid:2019804; rev:5; metadata:created_at 2014_11_25, signature_severity Major, updated_at 2024_04_12;)
Suricata
ET MALWARE Bossabot DDoS tool RFI attempt
suricata·2014-09-22·CVSS 9.8
CVE-2012-1823 [CRITICAL] ET MALWARE Bossabot DDoS tool RFI attempt
ET MALWARE Bossabot DDoS tool RFI attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET MALWARE Bossabot DDoS tool RFI attempt"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"php?-d|20|allow_url"; fast_pattern; content:"auto_prepend_file|3d|php|3a 2f|"; http.request_body; content:"<?php|0d 0a|"; startswith; reference:url,www.kernelmode.info/forum/viewtopic.php?f=16&t=3476&p=23965#p23965; reference:url,cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1823; classtype:trojan-activity; sid:2019212; rev:5; metadata:created_at 2014_09_22, signature_severity Major, tag CISA_KEV, updated_at 2024_04_13;)
Suricata
ET MALWARE EvilGrab/Vidgrab Checkin
suricata·2013-09-04
CVE-2012-0158 ET MALWARE EvilGrab/Vidgrab Checkin
ET MALWARE EvilGrab/Vidgrab Checkin
Rule: alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE EvilGrab/Vidgrab Checkin"; flow:established,to_server; content:"|7c 28|"; pcre:"/^\d{1,3}\x2e\d{1,3}\x2e\d{1,3}\x2e\d{1,3}/R"; content:"|29 7c|"; within:2; pcre:"/^\d{1,5}/R"; content:"|7c|Win"; within:4; reference:url,contagiodump.blogspot.com.br/2013/09/sandbox-miming-cve-2012-0158-in-mhtml.html; classtype:command-and-control; sid:2017413; rev:4; metadata:created_at 2013_09_04, signature_severity Major, updated_at 2024_03_06;)
Suricata
ET WEB_SPECIFIC_APPS MoinMoin twikidraw Action Traversal File Upload
suricata·2013-06-28
CVE-2012-6081 ET WEB_SPECIFIC_APPS MoinMoin twikidraw Action Traversal File Upload
ET WEB_SPECIFIC_APPS MoinMoin twikidraw Action Traversal File Upload
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS MoinMoin twikidraw Action Traversal File Upload"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"?action=twikidraw"; fast_pattern; content:"&target="; distance:0; content:"../moin.wsgi"; endswith; reference:bugtraq,57082; reference:cve,2012-6081; reference:url,packetstormsecurity.com/files/122079/moinmoin_twikidraw.rb.txt; reference:url,exploit-db.com/exploits/25304/; classtype:web-application-attack; sid:2017074; rev:6; metadata:created_at 2013_06_28, cve CVE_2012_6081, signature_severity Major, updated_at 2024_03_06, reviewed_at 2024_02_06;)
Suricata
ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
suricata·2013-06-13
CVE-2012-1533 ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection"; flow:established,to_client; file.data; content:"<jnlp"; nocase; content:"initial-heap-size"; nocase; content:"max-heap-size"; content:"-XXaltjvm"; nocase; fast_pattern; reference:cve,2012-1533; classtype:trojan-activity; sid:2017013; rev:4; metadata:created_at 2013_06_13, cve CVE_2012_1533, confidence Medium, signature_severity Major, updated_at 2024_03_13, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
Suricata
ET MALWARE CFR DRIVEBY CVE-2012-4792 DNS Query for C2 domain
suricata·2012-12-30·CVSS 8.8
CVE-2012-4792 [HIGH] ET MALWARE CFR DRIVEBY CVE-2012-4792 DNS Query for C2 domain
ET MALWARE CFR DRIVEBY CVE-2012-4792 DNS Query for C2 domain
Rule: alert dns $HOME_NET any -> any any (msg:"ET MALWARE CFR DRIVEBY CVE-2012-4792 DNS Query for C2 domain"; dns.query; content:"provide.yourtrap.com"; startswith; fast_pattern; nocase; endswith; reference:cve,2012-4792; reference:url,github.com/rapid7/metasploit-framework/commit/6cb9106218bde56fc5e8d72c66fbba9f11c24449; reference:url,eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/; classtype:command-and-control; sid:2016135; rev:7; metadata:affected_product Any, attack_target Client_Endpoint, created_at 2012_12_30, cve CVE_2012_4792, deployment Perimeter, confidence Medium, signature_severity Major, tag DriveBy, tag CISA_KEV, updated_at 2024_04_13;)
Suricata
ET WEB_CLIENT Microsoft Rich Text File .RTF File download with invalid listoverridecount
suricata·2012-12-12
CVE-2012-2539 ET WEB_CLIENT Microsoft Rich Text File .RTF File download with invalid listoverridecount
ET WEB_CLIENT Microsoft Rich Text File .RTF File download with invalid listoverridecount
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Microsoft Rich Text File .RTF File download with invalid listoverridecount"; flow:established,to_client; file.data; content:"|5c|listoverridetable"; distance:0; content:"|5c|listoverride|5c|"; fast_pattern; content:"|5c|listoverridecount"; isdataat:2,relative; pcre:"/^(?:0*?[19]\d|[^190])/R"; reference:cve,2012-2539; classtype:attempted-user; sid:2018315; rev:7; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2012_12_12, cve CVE_2012_2539, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_13;)
Suricata
ET WEB_CLIENT Microsoft Rich Text File download - SET
suricata·2012-10-10
CVE-2012-0183 ET WEB_CLIENT Microsoft Rich Text File download - SET
ET WEB_CLIENT Microsoft Rich Text File download - SET
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Microsoft Rich Text File download - SET"; flow:established,to_client; flowbits:set,ET.http.rtf.download; flowbits:noalert; file.data; content:"|7B 5C 72 74 66 31|"; within:6; reference:cve,2012-0183; classtype:attempted-user; sid:2015790; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2012_10_10, cve CVE_2012_0183, deployment Perimeter, confidence Medium, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_14;)
Suricata
ET WEB_CLIENT Microsoft Excel file download - SET 1
suricata·2012-05-10
CVE-2012-0185 ET WEB_CLIENT Microsoft Excel file download - SET 1
ET WEB_CLIENT Microsoft Excel file download - SET 1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Microsoft Excel file download - SET 1"; flow:established,to_client; flowbits:isset,OLE.CompoundFile; flowbits:set,ETPRO.Microsoft.Excel; flowbits:noalert; file.data; content:"|09 08 10 00 00 06 05 00|"; distance:512; content:"|57006F0072006B0062006F006F006B00|"; fast_pattern; reference:cve,2012-0185; classtype:attempted-user; sid:2025086; rev:9; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2012_05_10, cve CVE_2012_0185, deployment Perimeter, confidence Medium, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_14;)
Suricata
ET WEB_CLIENT Hostile Microsoft Rich Text File (RTF) with corrupted listoverride
suricata·2012-05-08
CVE-2012-0183 ET WEB_CLIENT Hostile Microsoft Rich Text File (RTF) with corrupted listoverride
ET WEB_CLIENT Hostile Microsoft Rich Text File (RTF) with corrupted listoverride
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Hostile Microsoft Rich Text File (RTF) with corrupted listoverride"; flow:established,to_client; flowbits:set,ETPRO.RTF; file.data; content:"|7b 5c 2a 5c|listoverridetable"; content:"|5c|listoverride|5c|"; fast_pattern; pcre:"/\x5clistoverride\x5c((?!\x5cls\d{1,4}\s*\}).)+?\x5clistoverride\x5c/s"; reference:cve,2012-0183; classtype:attempted-user; sid:2025085; rev:5; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2012_05_08, cve CVE_2012_0183, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_06;)
Suricata
ET DOS Microsoft Remote Desktop (RDP) Syn/Ack Outbound Flowbit Set
suricata·2012-03-15
CVE-2012-0152 ET DOS Microsoft Remote Desktop (RDP) Syn/Ack Outbound Flowbit Set
ET DOS Microsoft Remote Desktop (RDP) Syn/Ack Outbound Flowbit Set
Rule: alert tcp $HOME_NET 3389 -> any any (msg:"ET DOS Microsoft Remote Desktop (RDP) Syn/Ack Outbound Flowbit Set"; flow:from_server; flowbits:isnotset,ms.rdp.synack; flowbits:set,ms.rdp.synack; flowbits:noalert; flags:SA; reference:cve,2012-0152; classtype:not-suspicious; sid:2014385; rev:6; metadata:created_at 2012_03_15, cve CVE_2012_0152, signature_severity Major, updated_at 2024_03_14;)
Suricata
ET WEB_CLIENT Microsoft Windows Media component specific exploit
suricata·2012-01-28
CVE-2012-0003 ET WEB_CLIENT Microsoft Windows Media component specific exploit
ET WEB_CLIENT Microsoft Windows Media component specific exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Microsoft Windows Media component specific exploit"; flow:established,to_client; file.data; content:"bang()"; content:"cloned"; distance:0; content:"unescape(|22|%u0c0c%u0c0c%u0c0c%u0c0c%u0c0c%u0c0c|22|)"; fast_pattern; distance:0; reference:cve,2012-0003; classtype:attempted-user; sid:2014156; rev:7; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2012_01_28, cve CVE_2012_0003, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_08;)
Suricata
ET MALWARE Dooptroop CnC Beacon
suricata·2012-01-10
CVE-2011-3544 ET MALWARE Dooptroop CnC Beacon
ET MALWARE Dooptroop CnC Beacon
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Dooptroop CnC Beacon"; flow:established,to_server; http.method; content:"GET"; http.uri; content:".php?num="; fast_pattern; content:"&rev="; distance:0; pcre:"/^\/[a-z]+\.php\?num=\d+&rev=/"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,blog.eset.com/2012/03/17/drive-by-ftp-a-new-view-of-cve-2011-3544; classtype:command-and-control; sid:2014112; rev:7; metadata:attack_target Client_Endpoint, created_at 2012_01_10, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_20, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel;)
Suricata
ET WEB_SERVER ASP.NET Forms Authentication Bypass
suricata·2012-01-03
CVE-2011-3416 ET WEB_SERVER ASP.NET Forms Authentication Bypass
ET WEB_SERVER ASP.NET Forms Authentication Bypass
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER ASP.NET Forms Authentication Bypass"; flow:established,to_server; http.uri; content:"/CreatingUserAccounts.aspx"; fast_pattern; http.request_body; content:"CreateUserStepContainer"; content:"UserName="; distance:0; content:"%00"; distance:0; pcre:"/UserName\x3d[^\x26]+\x2500/"; reference:cve,2011-3416; classtype:attempted-user; sid:2014100; rev:7; metadata:created_at 2012_01_03, cve CVE_2011_3416, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Pub
No public exploits indexed.
http://osvdb.org/81756http://www.adobe.com/support/security/bulletins/apsb12-10.htmlhttp://www.securityfocus.com/bid/53422http://www.securitytracker.com/id?1027047https://exchange.xforce.ibmcloud.com/vulnerabilities/75447http://osvdb.org/81756http://www.adobe.com/support/security/bulletins/apsb12-10.htmlhttp://www.securityfocus.com/bid/53422http://www.securitytracker.com/id?1027047https://exchange.xforce.ibmcloud.com/vulnerabilities/75447
2012-05-09
Published