CVE-2012-4791Code Injection in Microsoft Exchange Server

CWE-94Code Injection3 documents3 sources
Severity
3.5LOWNVD
EPSS
33.3%
top 3.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 12
Latest updateMay 14

Description

Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/exchange_server2007, 2010+1

🔴Vulnerability Details

2
GHSA
GHSA-9994-2hp8-8394: Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang2022-05-14
CVEList
CVE-2012-4791: Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang2012-12-12
CVE-2012-4791 — Code Injection in Microsoft | cvebase