Vulnerabilities > CVE-2012-1527 - Numeric Errors vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 14 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS12-072 |
bulletin_url | |
date | 2012-11-13T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 2727528 |
knowledgebase_url | |
severity | Critical |
title | Vulnerabilities in Windows Shell Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS12-072.NASL |
description | The version of Windows on the remote host is affected by several vulnerabilities that could allow an attacker to execute arbitrary code on the system by causing a user to browse to a specially crafted briefcase in Windows Explorer. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 62904 |
published | 2012-11-14 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/62904 |
title | MS12-072: Vulnerabilities in Windows Shell Could Allow Remote Code Execution (2727528) |
code |
|
Oval
accepted | 2013-05-06T04:01:47.771-04:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
description | Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability." | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:15975 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2012-11-16T11:50:27 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
title | Windows Briefcase Integer Underflow Vulnerability - MS12-072 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
version | 76 |
References
- http://secunia.com/advisories/51221
- http://secunia.com/advisories/51221
- http://www.securitytracker.com/id?1027748
- http://www.securitytracker.com/id?1027748
- http://www.us-cert.gov/cas/techalerts/TA12-318A.html
- http://www.us-cert.gov/cas/techalerts/TA12-318A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-072
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-072
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15975
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15975