CVE-2012-5379 describes an untrusted search path vulnerability in ActivePython 3.2.2.3, specifically when installed in the C:\ directory. This flaw could allow a local attacker to gain privileges by introducing a malicious DLL into specific Python directories, which an administrator might inadvertently add to the system PATH. The vulnerability is rated as HIGH severity (CVSS 7.3), indicating a low attack complexity and local access requirement, with the potential for high impact on confidentiality, integrity, and availability. It requires user interaction (UI:R) for the malicious DLL to be loaded. Despite its severity, there is no evidence of active exploitation, and it is not listed in CISA's KEV catalog. While a Metasploit module (EDB-28130) exists, community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.2.3CPE matchmatch criteria | cpe:2.3:a:activestate:activepython:3.2.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.