CVE-2012-5896 describes a critical remote code execution vulnerability in the Annotation Objects Extension ActiveX control (AnnotateX.dll) within Quest InTrust 10.4.0.853 and earlier. This flaw, stemming from an improperly implemented Add method and an uninitialized pointer, allows remote attackers to execute arbitrary code by supplying a memory address as the first argument. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no authentication and having complete impact on confidentiality, integrity, and availability. Exploit code is publicly available via Metasploit modules and ExploitDB, indicating a high potential for exploitation, although it is not currently listed on the CISA KEV catalog and has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.4.0.853CPE matchmatch criteria | cpe:2.3:a:quest:intrust:*:*:*:*:*:*:*:* | ||
10.1CPE matchmatch criteria | cpe:2.3:a:quest:intrust:10.1:*:*:*:*:*:*:* | ||
10.2.5CPE matchmatch criteria | cpe:2.3:a:quest:intrust:10.2.5:*:*:*:*:*:*:* | ||
10.3CPE matchmatch criteria | cpe:2.3:a:quest:intrust:10.3:*:*:*:*:*:*:* | ||
10.4CPE matchmatch criteria | cpe:2.3:a:quest:intrust:10.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.