IBM Lotus Notes CVE-2012-2174 URL Handler Remote Code Execution Vulnerability
BID:54070
Info
IBM Lotus Notes CVE-2012-2174 URL Handler Remote Code Execution Vulnerability
| Bugtraq ID: | 54070 |
| Class: | Unknown |
| CVE: |
CVE-2012-2174 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2012 12:00AM |
| Updated: | Mar 19 2015 08:44AM |
| Credit: | Moritz Jodeit |
| Vulnerable: |
IBM Lotus Notes 8.5.3 IBM Lotus Notes 8.5.2 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.0.2 IBM Lotus Notes 8.5.2.3 IBM Lotus Notes 8.5.2.2 IBM Lotus Notes 8.5.2.1 IBM Lotus Notes 8.5.2.0 IBM Lotus Notes 8.5.1.5 IBM Lotus Notes 8.5.1.4 IBM Lotus Notes 8.5.1.3 IBM Lotus Notes 8.5.1.2 IBM Lotus Notes 8.5.1.1 IBM Lotus Notes 8.5.1.0 IBM Lotus Notes 8.5.0.1 IBM Lotus Notes 8.5.0.0 IBM Lotus Notes 8.5 IBM Lotus Notes 8.0.2.6 IBM Lotus Notes 8.0.2.5 IBM Lotus Notes 8.0.2.4 IBM Lotus Notes 8.0.2.3 IBM Lotus Notes 8.0.2.2 IBM Lotus Notes 8.0.2.1 IBM Lotus Notes 8.0.2.0 |
| Not Vulnerable: | |
Discussion
IBM Lotus Notes CVE-2012-2174 URL Handler Remote Code Execution Vulnerability
IBM Lotus Notes is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user.
IBM Lotus Notes versions 8.0.2, 8.5, 8.5.1, 8.5.2, and 8.5.3 are affected.
IBM Lotus Notes is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user.
IBM Lotus Notes versions 8.0.2, 8.5, 8.5.1, 8.5.2, and 8.5.3 are affected.
Exploit / POC
IBM Lotus Notes CVE-2012-2174 URL Handler Remote Code Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
IBM Lotus Notes CVE-2012-2174 URL Handler Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
IBM Lotus Notes CVE-2012-2174 URL Handler Remote Code Execution Vulnerability
References:
References: