CVE-2012-2423
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, provide different responses to remote requests depending on whether a…
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, provide different responses to remote requests depending on whether a ZIP pathname is valid, which allows remote attackers to obtain potentially sensitive information about the installation path and product version via a series of requests involving the Msxml2.XMLHTTP object.
- CVSS 2.0
- 1.8 LOWAV:A/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- intuit/quickbooks
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/232979US Government Resource
- http://www.securityfocus.com/archive/1/522139Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75174
- http://www.kb.cert.org/vuls/id/232979US Government Resource
- http://www.securityfocus.com/archive/1/522139Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75174
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.