Vulnerability Description
Multiple untrusted search path vulnerabilities in RealFlex RealWin before 2.1.13, FlexView before 3.1.86, and RealWinDemo before 2.1.13 allow local users to gain privileges via a Trojan horse (1) realwin.dll or (2) keyhook.dll file in the current working directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Realflex | Realwin | <= 2.1.12 |
| Realflex | Flexview | <= 3.1.85 |
| Realflex | Realwindemo | <= 2.1.12 |
References
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-251-01.pdfUS Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-251-01.pdfUS Government Resource
FAQ
What is CVE-2012-3004?
CVE-2012-3004 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Multiple untrusted search path vulnerabilities in RealFlex RealWin before 2.1.13, FlexView before 3.1.86, and RealWinDemo before 2.1.13 allow local users to gain privileges via a Trojan horse (1) real...
How severe is CVE-2012-3004?
CVE-2012-3004 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-3004?
Check the references section above for vendor advisories and patch information. Affected products include: Realflex Realwin, Realflex Flexview, Realflex Realwindemo.