CVE-2012-3022
The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict the creation of files, which allows remote attackers to download an arbitrary program onto a client…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict the creation of files, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted web site.
- CVSS 2.0
- 8.5 HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- canarylabs/trendlink
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-098-01.pdfUS Government Resource
- http://ics-cert.us-cert.gov/pdf/ICSA-13-098-01.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.