VulnerabilityModified
CVE-2012-5357
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
CRITICAL 9.8EPSS 67.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 67.78% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- ektron/ektron content management system
- Source
- cve@mitre.org
References
- http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htmIssue Tracking, Vendor Advisory
- https://technet.microsoft.com/library/security/msvr12-016Issue Tracking, Release Notes, Third Party Advisory
- https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/Exploit, Issue Tracking, Third Party Advisory
- https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_execExploit, Issue Tracking, Third Party Advisory
- http://documentation.ektron.com/current/ReleaseNotes/Release8/8.02SP5.htmIssue Tracking, Vendor Advisory
- https://technet.microsoft.com/library/security/msvr12-016Issue Tracking, Release Notes, Third Party Advisory
- https://webstersprodigy.net/2012/10/25/cve-2012-5357cve-1012-5358-cool-ektron-xslt-rce-bugs/Exploit, Issue Tracking, Third Party Advisory
- https://www.rapid7.com/db/modules/exploit/windows/http/ektron_xslt_execExploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.