Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-0013 | First vendor Publication | 2012-01-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0013 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14197 | |||
Oval ID: | oval:org.mitre.oval:def:14197 | ||
Title: | Assembly Execution Vulnerability | ||
Description: | Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2012-0013 | Version: | 4 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Microsoft Office ClickOnce Unsafe Execution | More info here |
ExploitDB Exploits
id | Description |
---|---|
2012-06-11 | MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability |
2012-01-14 | Microsoft Windows Assembly Execution Vulnerability MS12-005 |
OpenVAS Exploits
Date | Description |
---|---|
2012-01-11 | Name : Windows ClickOnce Application Installer Remote Code Execution Vulnerability (... File : nvt/secpod_ms12-005.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
78207 | Microsoft Windows Embedded ClickOnce Application Office File Handling Remote ... Microsoft Windows contains a flaw related to the way ClickOnce applications are embedded in Microsoft Office files. This may allow a context-dependent attacker to execute arbitrary code. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2012-01-12 | IAVM : 2012-A-0007 - Microsoft Windows Remote Code Execution Vulnerability Severity : Category II - VMSKEY : V0031010 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-09-17 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 51029 - Revision : 1 - Type : OS-WINDOWS |
2019-09-17 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 51028 - Revision : 1 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 26069 - Revision : 5 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 26068 - Revision : 5 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 26067 - Revision : 5 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 26066 - Revision : 5 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 21508 - Revision : 10 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 21507 - Revision : 10 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 21506 - Revision : 10 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 21505 - Revision : 10 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows Object Packager ClickOnce object remote code execution attempt RuleID : 21504 - Revision : 10 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows embedded packager object with .application extension bypass... RuleID : 20883 - Revision : 13 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Windows embedded packager object identifier RuleID : 20882 - Revision : 12 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Windows embedded packager object with .application extension bypass... RuleID : 20881 - Revision : 5 - Type : SPECIFIC-THREATS |
Metasploit Database
id | Description |
---|---|
2012-01-10 | MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-01-10 | Name : Opening a specially crafted Microsoft Office file could result in arbitrary c... File : smb_nt_ms12-005.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:03:08 |
|
2024-11-28 12:28:22 |
|
2024-08-02 12:18:37 |
|
2024-08-02 01:05:29 |
|
2024-02-02 01:18:05 |
|
2024-02-01 12:05:21 |
|
2023-12-07 21:28:01 |
|
2023-09-05 12:16:59 |
|
2023-09-05 01:05:13 |
|
2023-09-02 12:17:03 |
|
2023-09-02 01:05:19 |
|
2023-08-12 12:20:45 |
|
2023-08-12 01:05:20 |
|
2023-08-11 12:17:10 |
|
2023-08-11 01:05:29 |
|
2023-08-06 12:16:30 |
|
2023-08-06 01:05:20 |
|
2023-08-04 12:16:34 |
|
2023-08-04 01:05:20 |
|
2023-07-14 12:16:33 |
|
2023-07-14 01:05:18 |
|
2023-03-29 01:18:30 |
|
2023-03-28 12:05:26 |
|
2022-10-11 12:14:46 |
|
2022-10-11 01:05:01 |
|
2021-05-04 12:18:55 |
|
2021-04-22 01:22:38 |
|
2020-09-28 17:22:44 |
|
2020-05-23 13:16:58 |
|
2020-05-23 00:32:32 |
|
2019-05-09 12:04:25 |
|
2019-02-26 17:19:37 |
|
2018-10-31 00:20:16 |
|
2018-10-13 05:18:34 |
|
2018-09-20 12:09:29 |
|
2017-09-19 09:25:07 |
|
2016-09-30 01:03:30 |
|
2016-08-31 12:03:15 |
|
2016-08-05 12:03:35 |
|
2016-06-28 18:57:51 |
|
2016-04-26 21:22:35 |
|
2014-02-17 11:06:46 |
|
2014-01-19 21:28:18 |
|
2013-11-11 12:39:41 |
|
2013-05-10 22:30:43 |
|
2013-03-07 13:19:41 |
|